MS warns over zero-day IE bug2010.12.23 09:32 by Daniela
Keywords: Microsoft, IE, security
Microsoft warned on Wednesday of a new zero-day vulnerability in Internet Explorer.
The flaw creates a means for hackers to inject malware onto vulnerable systems, providing surfers are first tricked into visiting booby-trapped websites. As such the flaw poses a severe drive-by download risk.
All established version of IE (from 6 to 8) are affected. It's unclear whether or not the IE 9 beta is similarly vulnerable. The flaw reportedly involves the handling of Cascading Style Sheets by Microsoft's browser software. The bug first came to light on the seclists.org full disclosure mailing list earlier this month.
A module exploiting the bug – which is noteworthy because it defeats Data Execution Prevention (DEP) and Address Space Layout Randomisation (ASLR) security defences in Microsoft products – has been added by the Metasploit project.
Read more -here-