Security-X

Forum Security-X => News => Discussion démarrée par: SX-News le janvier 06, 2013, 20:59:07

Titre: [fsecure] Fix it: Internet Explorer 8 Vulnerability
Posté par: SX-News le janvier 06, 2013, 20:59:07
Fix it: Internet Explorer 8 Vulnerability

Description :  As mentioned in our previous post (http://"http://www.f-secure.com/weblog/archives/00002477.html"), there's an Internet Explorer (zero-day) remote code execution vulnerability being exploited in the wild which affects IE 8, as well as IE 6 & 7. Those versions of IE account for about one third of all desktop browser market share (http://"http://marketshare.hitslink.com/browser-market-share.aspx?qprid=2&qpcustomd=0").

Current exploitation is limited but it's quite likely a reliable exploit will soon find its way into crimeware exploit kits.

<img alt="Microsoft Security Advisory 2794220" border="0" height="212" src="http://www.f-secure.com/weblog/archives/MicrosoftSA_2794220.png" width="751" />
Microsoft Security Advisory (2794220 (http://"http://technet.microsoft.com/en-us/security/advisory/2794220"))

IE 9 &amp; 10 are not vulnerable &mdash; which is of small comfort to users of Windows XP as IE 9 &amp; 10 are not supported.

For consumers with XP, we recommend installing an additional browser such as Mozilla Firefox or Google Chrome.

For corporate folks (still) required to use XP with IE 8: Microsoft has a Fix it tool available.

<img alt="Microsoft Security Advisory 2794220, Fix it" border="0" height="265" src="http://www.f-secure.com/weblog/archives/MicrosoftSA_2794220_Fixit.png" width="630" />

You'll find more details at Microsoft's Security Research &amp; Defense blog: Microsoft "Fix it" available for Internet Explorer 6, 7, and 8 (http://"http://blogs.technet.com/b/srd/archive/2012/12/31/microsoft-quot-fix-it-quot-available-for-internet-explorer-6-7-and-8.aspx").

It's not yet clear if this vulnerability will be patched on January 8th during Microsoft's scheduled update cycle.






  On 02/01/13 At 11:12 AM

Lien : http://www.f-secure.com/weblog/archives/00002478.html