Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
    Digg this story   Add to del.icio.us  
Zero-day IE exploit
Published: 2005-11-22

Security researchers have published a zero-day exploit for Internet Explorer this week that allows remote code execution on most variants of Windows.

The vulnerability targeted by the exploit was originally announced in May as a stability issue resulting in the browser closing. With the release of the exploit code, however, security researchers have demonstrated that malicious code can be remotely executed after convincing a user to click on a link.

The public proof-of-concept exploit launches the Calculator included with Windows; however this could be easily modified to more malicious executables.

Microsoft has expressed concern that this new vulnerability was not disclosed to them first, potentially putting users at risk. Although there is currently no patch for this vulnerability, disabling Active Scripting or switching to an alternate browser such as Mozilla Firefox would effectively mitigate the risk.

Posted by: Peter Laborge
    Digg this story   Add to del.icio.us  
 
Comments Mode:
Zero-day IE exploit 2005-11-22
Don Parker (1 replies)
Re: Zero-day IE exploit 2005-11-23
Dbtech
Zero-day IE exploit 2005-11-23
auris
Zero-day IE exploit 2005-11-23
Jerry M. Gartner
Zero-day IE exploit 2005-11-23
Bob (1 replies)
Re: Zero-day IE exploit 2005-11-23
Jason (1 replies)
Re: Zero-day IE exploit 2005-11-23
Anonymous (1 replies)
Re: Re: Zero-day IE exploit 2005-12-02
Anonymous
Zero-day? 2005-11-29
Anonous (1 replies)
Re: Zero-day? 2005-12-02
Anonymous
Putting users at risk 2005-12-14
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus