Printed from http://www.electronista.com

Internet Explorer vulnerability affects all from version 6 to latest

updated 08:56 pm EDT, Sun April 27, 2014

Exploit targets Internet Explorer 9 to 11, flaw dates back to Internet Explorer 6

A recently-discovered security flaw in Internet Explorer has the potential to affect a wide number of Internet users, according to a security firm. Confirmed by Microsoft, the "zero-day" exploit found by FireEye targets Internet Explorer 9 through to version 11, though the vulnerability itself has been found to exist in all versions of the browser going back to Internet Explorer 6.

Revealed yesterday, the exploit takes advantage of a use-after-free vulnerability, using Flash to access memory and bypass Windows' ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) protection systems. In essence, an attacker able to coax a victim to visit a specially created site with a prepared Flash file could potentially execute code on the target computer, installing malware and gaining control of the PC.

The active exploit is being targeted in the last three versions of Internet Explorer, making up around 26 percent of the browser market in 2013. Microsoft advises that users installing the latest version of the Enhanced Mitigation Experience Toolkit, and to change Internet and Local intranet security zone settings to "High," among other items, with FireEye adding that the Enhanced Protected Mode in Internet Explorer 10 and later breaks the exploit, and disabling the Flash plug-in will prevent it from running in the first place.



By Electronista Staff
toggle

Comments

  1. Spheric Harlot

    Clinically Insane

    Joined: 11-07-99

    So this is actually a FLASH vulnerability?

  1. Mike Wuerthele

    Managing Editor

    Joined: 07-19-12

    Sort of. It's a Flash vulnerability that requires the exploited to be using IE to take advantage of.

Login Here

Not a member of the MacNN forums? Register now for free.

toggle

Network Headlines

Follow us on Facebook

toggle

Most Popular

Advertisement

Recent Reviews

Samsung Galaxy S6 Edge

The Samsung Galaxy S6 range is a critical component in Samsung's flagging smartphone strategy. With sales of its high-end smartphones ...

Notti smart lamp from Witti

Perhaps you've already seen our review of the Dotti LED display from Witti Design. Meet Notti, Dotti's "sibling". Notti is a softball ...

Seagate Personal Cloud (2-Bay)

When it comes to backing up files, many users are now looking to the myriad of cloud storage solutions available. There is no doubt th ...

Advertisement

toggle

Most Commented

 
toggle

Popular News