Exploits a plenty – IE / Excel (Firefox?)



There are a number of vulnerabilities that are currently unpatched, but have working publicly known exploits for Excel (*2) and Internet Explorer (2 vulnerabilities here as well.) Proof of Concept code has been released for both the Excel and Internet Explorer vulnerabilities. This means, with the code publicly available, it won’t be long before it’s bundled into other malware delivery structures…. You might look at alternative browsers, BUT…. be forewarned that one of these vulnerabilities appears to work on a fully patched install of Mozilla-Firefox. (According to Sans – the Secunia code doesn’t – but the full disclosure exploit code does affect Firefox.) I’ve seen word of early 1.5.0.5 builds being available – I wonder if that will be modified to fix this issue?


The Excel flaws have been talked about for a while, code is now available which ratchets up the concern around those. For web browsing – it might be worthwhile to consider browsers other than IE unless absolutely necessary. Yes, firefox is affected by one of these, but time to patch has typically been shorter for browsers OTHER than IE.

Avoid clicking links in unexpected emails/attachments in unexpected emails. It’s all a matter of trust….

For IE users – you might protect yourself by running as a limited user or one of the various programs that will let IE drop priviliges. Sandboxie.com might be one possibility for you.

–UPDATE — 6/30/06 –

It appears that Firefox IS NOT VULNERABLE to the above vulnerabilities. According to SANS there had been some initial concern that one of these vulnerability exploits also worked with Firefox. Further investigation has turned that out to be false. There’s also a brief comment at a mozillazine.org weblog on the issue (referring to the SANS post.)

Related Posts

Blog Traffic Exchange Related Posts
  • The "secure software" dilemma It's quite a dilemma when a software product is billed as more secure than another.... several days back when Mozilla Firefox released v. 1.5.0.4 which fixed a number of security issues, I saw someone comment "I thought firefox was supposed to be secure." I think there's a misunderstanding when it......
  • Exploit for Unpatched Internet Explorer vulnerability Well.... buckle your seatbelts it's going to be a bumpy start to the week. the securityfix as well as incidents.org are reporting on exploit code that has been released that takes advantage of an unpatched Internet Explorer vulnerability. According to the Sans institute diary entry... they have tested the exploit......
  • Microsoft vulnerability whack-a-mole continues..... Translation - Microsoft patched one vulnerability another surfaces.... Incidents.org brings us the frustrating news.... If you remember the month of browser bugs series of exploits back in July, there was a denial of service there that appears to have code execution after all. Coincidence or not, it got publicly released......
Blog Traffic Exchange Related Websites
  • FlashGet My Download I've been using FlashGet for so many years I don't even remember since when or what version it was when I tried it. At that time the software was still not very popular and most people that I knew used other download helper software. I knew about FlashGet from Download.com......
  • What Is A Cloud Virtual Server Solution And How Will It Work? In recent years, cloud computing has seen more and more use. It offers new options for storing files and using the web and serves the base for many a social networking site. Internet use and communication have become much easier with the use of a cloud virtual server. The name......
  • Google Chrome, Firefox, Internet Exlporer, Safari... WHICH INTERNET BROWSER DO I USE?! Unless you spend a lot of time reading the specifications and hard details of internet browsers, you probably don't know what half of internet browser reviewers are talking about.  When I read that Google Chrome uses the latest NVIDIA 8600 Graphics Unit, my head starts to explode a little.  And......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site