HomeinetWarning, new vulnerability in Internet Explorer

Beware, new vulnerability in Internet Explorer

Internet ExplorerResearchers from security firm FireEye have discovered a new zero-day Internet Explorer on a hacked website.

This particular exploit targets English versions of Internet Explorer 7 and 8 on Windows XP and IE8 on Windows 7. FireEye says their analysis shows that the vulnerability affects versions of IE 7, 8, 9, and 10.

The security firm did not say whether IE10 for Windows 8 was affected or whether they tested the new IE11 browser.

There are two vulnerabilities involved in the attack: an information disclosure vulnerability that the exploit uses to retrieve the timestamp from the PE headers of msvcrt.dll (part of the Microsoft Visual C++ runtime). The second is an out-of-bounds memory access vulnerability, which is used to execute code.

Multiple versions of msvcrt.dll are used for distribution, so the exploit sends the timestamp back to the attacker's server, which returns an out-of-bounds exploit specific to the user's version.

The exploit involves a “ROP chain,” according to FireEye. “ROP chain” stands for Address Space Layout Randomization (ASLR), a technique that is usually blocked by Address Space Layout Randomization (ASLR) and has been around since Windows Vista.

FireEye is currently working with Microsoft to resolve the issue. The report states that the vulnerability can be mitigated using Enhanced Mitigation Experience Toolkit (EMET) 4.0, with an apparent focus on msvcrt.dll. Be careful, as you may have copies of multiple versions of this DLL on your system.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS