Printed from http://www.electronista.com

Internet Explorer vulnerability affects all from version 6 to latest

updated 08:56 pm EDT, Sun April 27, 2014

Exploit targets Internet Explorer 9 to 11, flaw dates back to Internet Explorer 6

A recently-discovered security flaw in Internet Explorer has the potential to affect a wide number of Internet users, according to a security firm. Confirmed by Microsoft, the "zero-day" exploit found by FireEye targets Internet Explorer 9 through to version 11, though the vulnerability itself has been found to exist in all versions of the browser going back to Internet Explorer 6.

Revealed yesterday, the exploit takes advantage of a use-after-free vulnerability, using Flash to access memory and bypass Windows' ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) protection systems. In essence, an attacker able to coax a victim to visit a specially created site with a prepared Flash file could potentially execute code on the target computer, installing malware and gaining control of the PC.

The active exploit is being targeted in the last three versions of Internet Explorer, making up around 26 percent of the browser market in 2013. Microsoft advises that users installing the latest version of the Enhanced Mitigation Experience Toolkit, and to change Internet and Local intranet security zone settings to "High," among other items, with FireEye adding that the Enhanced Protected Mode in Internet Explorer 10 and later breaks the exploit, and disabling the Flash plug-in will prevent it from running in the first place.



By Electronista Staff
toggle

Comments

  1. Spheric Harlot

    Clinically Insane

    Joined: 11-07-99

    So this is actually a FLASH vulnerability?

  1. EstaNightshift

    MacNN Staff

    Joined: 07-19-12

    Sort of. It's a Flash vulnerability that requires the exploited to be using IE to take advantage of.

Login Here

Not a member of the MacNN forums? Register now for free.

toggle

Network Headlines

toggle

Most Popular

Sponsor

Recent Reviews

D-Link Wi-Fi Smart Plug

Home automation fans have been getting their fair share of gadgets and accessories in the last few years. Starting with light bulbs, a ...

Razer Kraken Pro headset

Gaming headphones are a challenge to get right, for a long list of reasons that are unique to the consumer buying them. Some shoppers ...

Patriot Aero Wireless Mobile Drive

Regardless of how large a tablet you buy, you always want more space. There's always one more movie or another album you'd cram on, if ...

Sponsor

toggle

Most Commented

 
toggle

Popular News