Portal IT :: News, download, directory


Search: Sunday 5 February 2012











Add to Google Add to My Yahoo!


  Add to Favorites   Set Home Page





« february 2012
s m t w t f s
29 30 31 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 1 2 3
4 5 6 7 8 9 10







New Internet Explorer 7 Vulnerability Discovered
Published on Security  |  December 11, 2008, 15:02

Microsoft just launched its monthly collection of patches and another flaw came up the radar: this time, it affects the Internet Explorer 7 browser.

Known as the Microsoft Internet Explorer 7 XML Zero-Day, the critical severity-level exploit would allow an attacker to run arbitrary code when a malicious website is visited.

"Internet Explorer remote code execution vulnerabilities have very high impacts since the source of the malicious payload can be across any site on the Internet," said Andre Protas, eEye's Director of Research and Preview Services. "An even more critical problem is generated when clients are administrators on their local hosts, which would run the malicious payload with Administrator credentials."

It seems that the exploit code for this flaw has become publicly available on various forums and exploitation attemps have already been spotted.

According to eEye, the flaw affects both IE7 on Windows XP and on Windows Server 2003. Windows Vista was reported as well as vulnerable, but not targeted at present time.

Microsoft admitted the existence of the flaw but has yet to announce when a patch will be released.




Rate this       Low   High
Curent Rating: 3.1/5 by 14 users
 Print       Email      IM 




 
More Security News
 
Daily News Alert

 
Advertising
 
Top Rated Security News This Month