MS IE Javascript exploit for zero-day (0-day) vulnerability



An exploit for last weeks zero-day (0-day) javascript vulnerability in Microsoft’s Internet Explorer is in the wild. I saw this post from Sunbelt a couple nights ago go up and disappear, at the time I didn’t have long enough to read it… It’s back today and there are instructions for mitigating the risk. However, there is still no patch from Microsoft and no word on when to expect one. According to the Sunbelt post the exploit in the wild is being used for browser hijacking/spyware install stuff.


The Incidents.org handlers diary chimes in too musing on whether we’ll have an out of cycle patch, or if MS will wait until December 13th. MS has updated their security advisory, so Incidents is betting on an early/out of cycle fix. Hope that’s the case.

PC Pro also has an article on this today.

–update– 12/1/05–

The securityfix has it this morning along with connecting the dots to yesterday’s beta release of Microsoft’s antivirus software and promotion of the Windows Live Safety Center. The last time MS did antivirus, one of the big complaints was essentially lagging/sluggish response in the realm of updates (which for antivirus is critical). With the purchase of GeCad, they have a good antivirus structure, my main question will be if they can give the frequent updates it deserves. (With security patches now coming out only once a month, many times in spite of known vulnerabilities, I wonder…)

Anyway, Microsoft has an entry in their “Malicious software encyclopedia” for the worm installed by the “in the wild” exploit Trojan Downloader information.

The register has more on Windows OneCare Live beta. (OneCare is the name for Microsoft’s new antivirus package.)

Related Posts

Blog Traffic Exchange Related Posts
  • Network Security guide for the home or small business network - Part 12 - Antispyware I've talked about Antivirus software as an essential. Today we're going to look at Antispyware software. There is a difference. By definition a virus is a piece of software that infects other files or copies itself. A worm is a virus that spreads without user intervention. (From one open network......
  • Microsoft May 2006 patch Tuesday updates Now that the April patches have been patched.... it's time to look forward to what updates we'll be seeing from Microsoft this coming Tuesday May 9th... There are 3 expected updates for May, 2 for Windows and one for Exchange Server. The Exchange update is listed as critical as is......
  • Remove Windows Police Pro I'm seeing a lot of searches for how to remove Windows Police Pro this evening. It looks like it's ALSO the latest flavor of the minute in the rogue security application crowd (take a look at remove Green AV for another rogue). As stated before... my usual path for removing......
Blog Traffic Exchange Related Websites
  • Review of Windows Live Writer When you find a tool that makes life easier, there is nothing more exciting. The need for corporations to simplify and systematize their processes has to do with working smart and taking advantage of things that allow workers to reach their goals without having to work quite as hard. One......
  • Microsoft Issues “Cyber Monday” Security Shopping Tips for Consumers Monday, November 29 will be this year’s Cyber Monday,  the Monday following the Friday after Thanksgiving Day, and the second busiest online shopping day of the year in the United States.  Cyber Monday is also one of the busiest online shopping days in the United Kingdom, Germany, and France. For the millions of shoppers worldwide......
  • How to Install a Home Security System: Most Common Pitfalls Installing a home security system might seem easy. To be sure, it’s a lot easier to install one today than it was just a decade ago. Inexpensive consumer electronics components combined with robust wireless technology means that even an amateur can put in a decent system. Just because it’s easy,......
PDF24    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site