A zero day exploit is released for Internet Explorer

HP researchers published a zero day που μπορεί να χρησιμοποιηθεί για επιθέσεις σε μια αδυναμία του . The researchers published the exploit after Microsoft refused to issue a patch.

In a post on the company's blog, Dustin Childs, HP's senior security content developer, said the exploit publishing move could be considered "bad," but he followed the disclosure policy.zero day ie

"Microsoft has confirmed to us that it does not intend to release a patch for the security breach, and we felt the need to release the information to the public," said Childs.

The bug allows an attacker to bypass the Address Space attribute Randomization (ASLR), το οποίο ενεργεί ως μία από τις πολλές γραμμές άμυνας στο δημοφιλές πρόγραμμα περιήγησης.

Zero day exploit affects only 32-bit systems, but HP researchers said the error still affects millions of systems, even if most of them are now 64-bit.

Childs, who reported the error to Microsoft, said the response from the company was "technically correct." He thus punished the company's decision not to correct the error.

The HP Team even a PoC was released which proves that the error exists in the and 8.1.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).