Security firm FireEye Labs has discovered a new zero-day vulnerability in Internet Explorer 9 and 10. The vulnerability allows an attacker to install malware on unpatched systems.
According to their research, the attack is carried out using a website whose HTML code has been modified by the attacker.
“The attacker’s HTML/JavaScript web page runs a Flash object , which orchestrates the rest of the exploit . The exploit targets an IE 10 vulnerability that is embedded in JavaScript,” FireEye Labs explains.
So far, the vulnerability has been shown to affect versions of Internet Explorer 9 and 10 that use Adobe Flash, while Microsoft confirms that it is currently investigating the reports and trying to determine how the exploit works.
“Microsoft is aware of the limited, targeted attacks against Internet Explorer 9 and 10”, said a Microsoft spokesperson to TNW . ” As our research continues, we recommend our customers upgrade to Internet Explorer 11 for additional protection.”

