Internet Explorer users warned of new zero-day attacks

Filed Under: Internet Explorer, Malware, Microsoft, Vulnerability

Danger!
Microsoft has warned users of all supported versions of the Internet Explorer browser that an unpatched vulnerability exists in the product that is being actively exploited by malicious hackers in targeted attacks.

The zero-day vulnerability, described in a Microsoft's security advisory, allows cybercriminals to execute code on remote users' computers without their permission.

In other words, simply clicking on a link in an email could take you to a webpage which would silently install malicious code (such as a backdoor Trojan horse) onto your computer. In short, you could be one click away from having a hacker access your computer or comandeer it into being part of a botnet.

Sophos is adding detection of the malicious webapges as Mal/20103962-A, and the Trojan horse that we have seen being downloaded as Troj/GIFDldr-A.

According to Microsoft's advisory, Data Execution Prevention (DEP) - which is enabled by default in Internet Explorer 8 on Windows XP SP3, Windows Vista SP1, Windows Vista SP2, and Windows 7 - helps to protect against the attacks.

All eyes will now be on Microsoft to see how quickly they can issue a fix for this vulnerability - it would certainly be impressive if they managed to roll-out a patch in time for next Tuesday's "Patch Tuesday", but that may be a little optimistic.

, , ,

5 Responses to Internet Explorer users warned of new zero-day attacks

  1. renee says:

    this is why i use Chrome and Firefox!

    • JAC says:

      Cool, now google will archive your full identity with full credentials to every site you visit!

      • jack says:

        absolutely, not cool google chrome, it's the reason why i DON'T use it....
        personally i use principally Safari (i'm on Mac OS X 10.6, (snow leopard), and never had problems like this. only some malvare detected by MacScan.... (google malvares principally)....
        jack

        • JAC says:

          I agree. was merely showing my disdain for "renee" using chrome

        • Dino says:

          Personally, I use IE, only ever go to trusted sites or click on links from known sources, and have never (touch wood) had a virus or other problem...

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title="" rel=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <pre> <q cite=""> <strike> <strong>

About the author

Graham Cluley has worked in the computer security industry for more than 20 years, developing anti-virus software and doing quite a lot of talking about internet threats. He's won awards for his blogging, but is proudest of the text adventure games he wrote when he was still wearing short trousers. You can learn more about those (the games, not the trousers) at grahamcluley.com. Send Graham an email, subscribe to his updates on Facebook, follow him on Twitter and App.net, and circle him on Google Plus for regular updates.