24 May, 2013
News Channel – Mind Processors
times-of-indiabbc-news
cnet-newsyahoo-newsApple-newsgoogle-newsmsnbc-newscnn-newsfox-news
Skip to content
  • Home
  • Technology
    • Gadgets
    • Hardware
    • Software
    • Innovations
    • Linux
    • Open Source
    • Science
    • Telecom
    • Wireless
  • Business Tech
    • Eco-Bizz
    • Global Leaders
      • Apple
      • Google
      • Intel
      • Microsoft
      • Yahoo
    • Research
    • Politics & Law
  • Mind Processors
  • Gaming
    • News & Features
    • Playstation
    • X-Box
    • PC
    • Reviews
  • Security
  • Web
    • Social Media
  • Video
  • More
  • Subscribe
Follow @mindprocessors
Web Hosting Mindprocessors

IE flaw may allow Windows PCs to be hijacked, Microsoft warns

Posted on December 31, 2012 by Source: news.cnet.com
Tweet

Zero-day vulnerability affects versions of the Web browser from IE 6 through IE 8 but not later versions, the company says in a security advisory.

IE flaw may allow Windows PCs to be hijacked, Microsoft warns
Microsoft has confirmed that a zero-day vulnerability affecting older versions of Internet Explorer could allow attackers to gain control of Windows-based computers to host malicious Web sites.

The company acknowledged the issue in a security advisory yesterday that included advice on how users can mitigate the threat posed by the flaw.

“Microsoft is aware of targeted attacks that attempt to exploit this vulnerability through Internet Explorer 8,” Microsoft said, noting that more recent versions of the Web browser, including IE 9 and IE 10, were unaffected.

The remote code execution vulnerability affects the way the browser accesses memory, allowing an attacker to use the corrupted PC to host a Web site designed to exploit the vulnerability with other users.

In a web-based attack scenario, an attacker could host a website that contains a webpage that is used to exploit this vulnerability. In addition, compromised websites and websites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these websites. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes users to the attacker’s website.

The flaw has reportedly been used to exploit Windows PC users who visited the Web site for the Council on Foreign Relations, a nonpartisan think tank specializing in U.S. foreign policy and international affairs. The site has been hosting the malicious code since at least December 21, Darien Kindlund, senior staff scientist at security advisor FireEye, wrote in a blog Friday.

“We can also confirm that the malicious content hosted on the website does appear to use Adobe Flash to generate a heap spray attack against Internet Explorer version 8.0 (fully patched), which was the source of the zero-day vulnerability,” Kindlund wrote.

CNET has contacted Microsoft for more information and will update this report when we learn more.

Related Post

  • Twitter releases its handcrafted Windows 8 app
  • How Microsoft’s Surface tablet was born
  • Gates, Zuckerberg: Kids, learn to code
  • Why iWatch is a better idea for Apple than iTV
  • 50 million compromised in Evernote hack
  • Posted in Microsoft and tagged flaw, Internet Explorer, Microsoft', vulnerability, zero day.Bookmark this post.

    Comments are closed.

    CompUSA
    • Recent Posts

      • Planck satellite: Esa to release maps of ancient light
      • Nvidia unveils virtual graphics server in push beyond PCs
      • Google Maps climbs world’s tallest mountains
      • Congress hears options for asteroid defense: Pay now or pray later
      • New Lizard Species Look Like Evil Dinosaur Hybrids
    • Subscribe News


    • Recent Comments

      • Kirk on Groupon launches credit card payment business to compete with Paypal
      • Green Bay Packers on Steve Jobs better career role model than Obama: Survey
      • MBT Women Shoes on HR checking candidates’ background on FB, Twitter, Google
      • sexleksaker on Facebook suspends photo tag tool in Europe
      • cbn grinding wheels on Aquarium releases 655-pound sea turtle off Cape Cod after treatment
    • Archives

      • March 2013
      • February 2013
      • January 2013
      • December 2012
      • November 2012
      • October 2012
      • September 2012
      • August 2012
      • July 2012
      • June 2012
      • May 2012
      • April 2012
      • March 2012
      • February 2012
      • January 2012
      • December 2011
      • November 2011
      • October 2011
      • September 2011
      • August 2011
    • Tags

      Amazon American Android Anonymous Apple AT&T BlackBerry California China computer Earth email Europe Facebook Gmail Google+ India Internet iOS iPad iPhone Japan London Mark Zuckerberg Microsoft Microsoft' mobile NASA New York Samsung smartphone smartphones social network Software Sony space Steve Jobs tablet tablets Twitter U.S. Windows Windows 8 Yahoo YouTube
    Latest News:-
    • Planck satellite: Esa to release maps of ancient light
    • Nvidia unveils virtual graphics server in push beyond PCs
    • Google Maps climbs world’s tallest mountains
    • Congress hears options for asteroid defense: Pay now or pray later
    • New Lizard Species Look Like Evil Dinosaur Hybrids
    • Curiosity breaks rock to reveal dazzling white interior

    Categories

    • - Business Tech
    • - Security
    • - Technology
    • - Gadgets
    • - Gaming
    • - Global Leaders
    • - Web

    Official Connections

    • - TheQueries.com
    • - Blog.MindProcessors.com
    • - Forum.MindProcessors.com
    • - Blog.AbhilashShukla.info
    • - MindProcessors.com
    • - Web.MindProcessors.com

    Disclaimer

    • Our news channel is intended to provide quality news from top online news providing companies. This channel is a collection of quality and best news at one place. The news and the logos of other providers are completely their own property.

    Where else we are

    • - Connect with us on FaceBook
    • - Follow us on Twitter
    • - Subscribe to our Youtube Channel
    • - Connect via LinkedIn
    • - Find us on Google+
    © 2011 Mind Processors Technologies, All rights reserved.
    • About us
    • Contact Us
    • Careers
    • Privacy Policy
    • Terms & Conditions
    • Sitemap