News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Disaster Recovery More Topics...
Microsoft/Windows
Average Rating:
Rate this article:  
Remote-Code Vulnerability Being Exploited in IE 6 and 7 Remote-Code Vulnerability Being Exploited in IE 6 and 7
By Jennifer LeClaire
March 9, 2010 1:51PM

    Bookmark and Share
A flaw in Internet Explorer versions 6 and 7 is under active attack, Microsoft has warned. An invalid pointer reference in IE lets attackers execute code remotely. Microsoft said Internet Explorer 8 is not affected. Microsoft noted some mitigating factors, including having IE in protected mode and the need to visit a malware site.
 


Older versions of Internet Explorer are under attack. Microsoft warned Tuesday afternoon that cybercriminals are actively exploiting a security Relevant Products/Services vulnerability that lets attackers execute malicious code from remote locations.

Microsoft's internal investigation reveals that the latest version of the browser, Internet Explorer 8, is not affected. Likewise, Internet Explorer 5.01 Service Pack 4 on Microsoft Windows Relevant Products/Services 2000 Service Pack 4 is not affected.

Here's a quick list of affected versions for IT Relevant Products/Services administrators looking to implement a workaround to mitigate the risk: Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6 and Internet Explorer 7.

"In addition to Microsoft's Patch Tuesday updates today, the company also issued an advisory for a new zero-day vulnerability affecting Internet Explorer," said Josh Talbot, security intelligence manager for Symantec Security Response. "Symantec has observed exploitation of this vulnerability in the wild and has created Trojan.Malscript!html and JS.Downloader detection to mitigate this attack."

The Root of the Problem

Microsoft said the vulnerability exists due to an invalid pointer reference being used within Internet Explorer. Under certain conditions, it's possible for the invalid pointer to be accessed after an object is deleted, according to a March 9 Microsoft security advisory. In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution.

"At this time, we are aware of targeted attacks attempting to use this vulnerability. We will continue to monitor the threat environment and update this advisory if this situation changes," Microsoft said. "On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer Relevant Products/Services needs."

Mitigating Factors

IT administrators can take heart in the mitigating factors that may protect their organizations from zero-day attacks. First, Microsoft said the protected mode in Internet Explorer on Windows Vista and later Windows operating systems helps to limit the impact of the vulnerability, as an attacker who successfully exploited this vulnerability would have very limited rights on the system.

"In a web-based attack scenario, an attacker could host a web site that contains a web page that is used to exploit this vulnerability. In addition, compromised web sites and web sites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these web sites," Microsoft said. "Instead, an attacker would have to convince users to visit the web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker's web site."

By default, Internet Explorer on Windows Server 2003 and Windows Server 2008 runs in a restricted mode that is known as Enhanced Security Configuration. Microsoft said this mode sets the security level for the Internet zone to high. This is a mitigating factor for web sites that have not been added to the Internet Explorer trusted sites zone.

Finally, supported versions of Microsoft Outlook, Microsoft Outlook Express, and Windows Mail open HTML e-mail messages in the restricted sites zone by default. Microsoft said this removes the risk of an attacker being able to use this vulnerability to execute malicious code.
 

Tell Us What You Think
Comment:

Name:



Advertisement


 Microsoft/Windows
1.   Windows 7 Being Retooled for Tablets
2.   Free Tools Fix Shortcut Vulnerability
3.   Windows 7, Office Boost Microsoft
4.   Microsoft Warns of Shortcut Attacks
5.   MS Cofounder To Donate Fortune


advertisement
Windows 7 Being Retooled for TabletsWindows 7 Being Retooled for Tablets
Ballmer expects Microsoft To dominate.
Average Rating:
Windows 7, Office Boost MicrosoftWindows 7, Office Boost Microsoft
Aged PCs, servers being replaced.
Average Rating:
Outlook Connects To Social NetworksOutlook Connects To Social Networks
Multiple Office versions available.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Disaster Recovery | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Cloud & Virtualization | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.