Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
Microsoft has confirmed the presence of a zero-day vulnerability impacting Internet Explorer (IE) versions 6 and 7.The software giant said in an advisory that the flaw "exists as a null pointer reference of Internet Explorer" and involves the way the browser handles cascading style sheets objects. Attackers may be able to execute code on victims' machines if they can persuade them to visit a malicious website.In addition, cybercriminals can compromise trusted websites to perpetrate the attack, said Michael Sutton, vice president of security research at security firm Zscaler. “Internet Explorer versions 6 and 7 account for approximately 41 percent of web browsers in use today, so this vulnerability will be an enticing one for attackers,” he said. “Attacks such as these are also prime candidates for targeting otherwise legitimate websites as an attack vector. The exploit can be triggered simply via HTML code, so attackers can inject code into websites with weak security protections.” According to Symantec experts, reliable proof-of-concept code has yet to be published, but it is expected.There have been no reports of in-the-wild exploits, according to the advisory. IE8 is not affected.Microsoft listed a number of suggestions that users can take to reduce the possibility of being hit by an exploit. They include mitigating actions, such as running IE7 in "Protected Mode", and workarounds, including setting internet and intranet security zone settings to "high" before running ActiveX controls.Company engineers are working on a patch, and plan to release it as sson as it is cleared for widespread distribution. Microsoft's next scheduled security update release is December 8, but the firm occasionally issues out-of-band fixes for emergency vulnerabilities."Together with our partners, we will continue to monitor the threat landscape and will take action against any websites that seek to exploit this vulnerability," Jerry Bryant, senior security program manager at Microsoft, said in a blog post.See original article on scmagazineus.com
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.