Showing posts with label IE Zero-Day. Show all posts
Showing posts with label IE Zero-Day. Show all posts

Thursday, 20 August 2015

Churchgoers Attacked Through New Explorer Leak



The zero-day vulnerability in Internet Explorer for which Microsoft Tuesday an emergency patch released is used to infect visitors of an evangelical church in Hong Kong with malware. Attackers had placed an iframe on the denomination's website, which visitors sent by unnoticed to a website with an exploit. This exploit took advantage of the vulnerability that was present in IE7 to IE11.

In the case the attack was successful Korplug the malware was installed, says Symantec. Korplug is a Trojan horse designed to steal information. Through the malware attackers full control over the computer. According to anti-virus company, there was a so-called "watering hole" attacks, where attackers hacking websites which potential targets already visit on its own. In this way, the attackers do not have phishing emails to be sent, so that the longer attack may go unnoticed. In giving the emergency patch Microsoft had already indicated that the leak was actively attacked.

Wednesday, 19 August 2015

Microsoft Emergency Patch For Active Attacked IE Flaw



Microsoft has released an emergency patch released for a critical vulnerability in Internet Explorer that is actively used to infect computers with malware. Visiting a hacked or malicious Web site or see the getting infected ads is sufficient to execute the attacker to run arbitrary code on the computer.

It should be noted that the attacker could execute code with the rights of the logged in user. The impact may therefore be less if users who have an account with reduced logging rights, Microsoft said. The vulnerability was already attacked before the patch was available from Microsoft. What kind of attack it is and who the target was not reported.

The vulnerability, which was reported to Microsoft by a Google researcher, is present in IE7 on Windows Vista to IE11 on Windows 10. Because of the impact users get the advice Security Bulletin MS015-093 install immediately. On most computers, however, will automatically happen.