Beware, new vulnerability in Internet Explorer

Internet ExplorerResearchers by FireEye security company have identified a new zero-day exploit Discover on a hacked website.

This exploit targets English versions of Internet Explorer 7 and 8 in Windows XP and IE8 in Windows 7. OR FireEye says their analysis shows that vulnerability affects the versions of IE 7, 8, 9 and 10.

The security company did not report whether IE10 for Windows 8 was affected or tested the new IE11 browser.

There are two που εμπλέκονται στην επίθεση: η ευπάθεια αποκάλυψης πληροφοριών την οποία το exploit χρησιμοποιεί για να ανακτήσει το timestamp από τις κεφαλίδες PE του msvcrt.dll (part of Microsoft Visual C ++ runtime). The second is an out-of-bounds memory access vulnerability used to run code.

Many versions of msvcrt.dll are used for distribution, so exploit sends the timestamp back to the attacker's server, which returns a out-of-bounds exploit especially for of the user.

Το exploit περιλαμβάνει ένα “ROP chain” σύμφωνα με την FireEye. Το “ROP chain” σημαίνει Space Layout Randomization (ASLR), μια τεχνική που συνήθως μπλοκάρεται από την τυχαία ρύθμιση της ς Address Space ( ASLR ) και υπάρχει από τα Windows Vista και μετά.

FireEye is currently working with Microsoft to solve the problem. The report states that vulnerability can be mitigated by its use Enhanced Mitigation Experience Toolkit (EMET) 4.0, Microsoft's obvious emphasis on msvcrt.dll. Be careful as you may have copies of multiple versions of this DLL on your system.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).