Printed from http://www.electronista.com

Internet Explorer vulnerability affects all from version 6 to latest

updated 08:56 pm EDT, Sun April 27, 2014

Exploit targets Internet Explorer 9 to 11, flaw dates back to Internet Explorer 6

A recently-discovered security flaw in Internet Explorer has the potential to affect a wide number of Internet users, according to a security firm. Confirmed by Microsoft, the "zero-day" exploit found by FireEye targets Internet Explorer 9 through to version 11, though the vulnerability itself has been found to exist in all versions of the browser going back to Internet Explorer 6.

Revealed yesterday, the exploit takes advantage of a use-after-free vulnerability, using Flash to access memory and bypass Windows' ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) protection systems. In essence, an attacker able to coax a victim to visit a specially created site with a prepared Flash file could potentially execute code on the target computer, installing malware and gaining control of the PC.

The active exploit is being targeted in the last three versions of Internet Explorer, making up around 26 percent of the browser market in 2013. Microsoft advises that users installing the latest version of the Enhanced Mitigation Experience Toolkit, and to change Internet and Local intranet security zone settings to "High," among other items, with FireEye adding that the Enhanced Protected Mode in Internet Explorer 10 and later breaks the exploit, and disabling the Flash plug-in will prevent it from running in the first place.



By Electronista Staff
toggle

Comments

  1. Spheric Harlot

    Clinically Insane

    Joined: 11-07-99

    So this is actually a FLASH vulnerability?

  1. EstaNightshift

    Managing Editor

    Joined: 07-19-12

    Sort of. It's a Flash vulnerability that requires the exploited to be using IE to take advantage of.

Login Here

Not a member of the MacNN forums? Register now for free.

toggle

Network Headlines

toggle

Most Popular

Sponsor

Recent Reviews

Adesso Compagno X Bluetooth keyboard

The shift from typing on physical keyboards to digital versions on smartphones and tablets hasn't been an easy for many consumers. Fro ...

Polk Audio 4 Shot headset

Sound quality and design are two of the biggest areas of focus for manufacturers when coming up with a new gaming headset. Depending o ...

Patriot Supersonic Phoenix USB 3.0 drive

USB thumb drives aren't the end all solutions for data transfer and traveling needs. Sometimes people want something with a little mor ...

Sponsor

toggle

Most Commented

 
toggle

Popular News