Showing posts with label internet explorer. Show all posts
Showing posts with label internet explorer. Show all posts

Monday, January 20, 2020

Vulnerability In Internet Explorer

There has been found a vulnerability (CVE-2020-0674) affecting Microsoft Internet Explorer browsers. The vulnerability is related to the way that the scripting engine handles objects in memory in Internet Explorer. By exploiting the vulnerability an attacker may execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights an attacker may be able to take control of an affected system. Microsoft is aware of some targeted attacks exploiting the vulnerability.

Affected:
Internet Explorer 9, 10 and 11

At the moment of writing this there is no update available against the vulnerability. Microsoft has published a workaround while it's working on the update. More information here.

Friday, September 27, 2019

Scripting Engine Vulnerability Fixed In Internet Explorer

Microsoft have released an update to Internet Explorer web browsers. The update contains a fix to scripting engine memory corruption vulnerability (CVE-2019-1367). By exploiting the vulnerability an attacker may be able to execute arbitrary code and get the same user rights as the current user.

Affected versions
-Internet Explorer 9, 10 and 11

More information and instructions for updating can be read in the correspondent security advisory

Friday, December 21, 2018

Critical Vulnerability In Internet Explorer

There has been found a critical vulnerability in Microsoft Internet Explorer. The vulnerability (CVE-2018-8653) is in Internet Explorer's Jscript engine and by exploiting the vulnerability an attacker could execute arbitrary code in the context of the current user. A web-based attack example could be that an attacker hosts a specifically crafted website that is designed to exploit the vulnerability and lures user to view the website (for example by sharing a link in an email message).

The vulnerability is being exploited in targeted attacks and it is recommended to apply the patch as soon as possible. More information (patch instructions included) can be read from the related advisory.

Sunday, August 10, 2014

Internet Explorer To Block Outdated ActiveX Controls

Starting August 12th Microsoft is going to release an update for Internet Explorer that will start blocking out-of-date ActiveX controls. "ActiveX controls are small apps that let Web sites provide content, like videos and games, and let you interact with content like toolbars. Unfortunately, because many ActiveX controls aren’t automatically updated, they can become outdated as new versions are released. It’s very important that you keep your ActiveX controls up-to-date because malicious or compromised Web pages can target security flaws in outdated controls to collect information, install dangerous software, or by let someone else control your computer remotely."

More information about the upcoming feature can be read from the related blog post.

Tuesday, April 29, 2014

Vulnerability In Internet Explorer

Microsoft is aware of a vulnerability affecting Internet Explorer web browser 6-11 versions. The vulnerability (CVE-2014-1776) could allow remote code execution if a user opens a specially crafted website using an affected version of Internet Explorer.

At the moment there is no patch for the vulnerability available. For a workaround and more information please see the related security advisory.

Saturday, February 22, 2014

Vulnerability In Internet Explorer

Microsoft is aware of limited, targeted attacks attempting exploit a vulnerability in Internet Explorer. By exploiting the vulnerability successfully an attacker may be able to execute arbitrary code in affected system.

Affected are:
Internet Explorer 9 and 10 versions

At the moment there is no patch for the vulnerability available. For a workaround and more information please see the related security advisory.

Friday, September 20, 2013

Vulnerability In Internet Explorer

There has been found a vulnerability (CVE-2013-3893) in Microsoft Internet Explorer that may allow an attacker to execute arbitrary code in vulnerable system. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability in Internet Explorer 8 and 9 versions. However, the issue affects all Internet Explorer versions from 6 to 11.

At the moment, there is no patch released against the vulnerability. About workarouds can be read here.

Monday, May 6, 2013

Vulnerability In Internet Explorer

There has been found a vulnerability in Microsoft Internet Explorer that may allow an attacker to execute arbitrary code in vulnerable system. Microsoft is aware of attacks that try to exploit this vulnerability. Affected Internet Explorer version is 8.

At the moment, there is no patch released againts the vulnerability. About workarounds can be read here.

Sunday, December 30, 2012

Unpatched Vulnerability In Internet Explorer

There has been found a vulnerability in Microsoft Internet Explorer that may allow an attacker to execute arbitrary code in vulnerable system. The vulnerability is currently actively exploited. Internet Explorer 9 and 10 are not known to be affected by this vulnerability.

At the moment, there is no patch released againts the vulnerability. About workarouds can be read here.

Update:
Microsoft have released  MS13-008 to fix this issue.

Tuesday, March 15, 2011

Internet Explorer 9 Released

Microsoft has released version 9 of their Internet Explorer (IE) web browser. IE9 brings new features like faster browsing experience and different security and privacy related features like ActiveX Filtering and Tracking Protection.

More information about Internet Explorer can be read from IEBlog at MSDN.

Internet Explorer 9 can be downloaded here.

Wednesday, November 3, 2010

Unpatched Vulnerability In Internet Explorer

Microsoft is investigating public report of new vulnerability in supported versions of Internet Explorer. "The vulnerability exists due to an invalid flag reference within Internet Explorer. It is possible under certain conditions for the invalid flag reference to be accessed after an object is deleted. In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution." Microsoft states that they are aware of targeted attacks trying to exploit the vulnerability.

Information about workarounds and mitigations for the issue can be read from Microsoft's security advisory.

Friday, May 14, 2010

Mozilla Plugin Checker To Check Other Browsers' Plugins Too

Last fall Mozilla made available a website that Firefox users could use to check if their browser plugins were outdated. Now Mozilla has extended the plugin check to other browsers too. At the moment, supported are Safari 4, Chrome 4 and Opera 10.5. Support for the most popular, but not for all yet, plugins of Internet Explorer 7 and 8 is included too.

More information in Mozilla blog.

Tuesday, March 30, 2010

Out-Of-Band Update For Internet Explorer Released

Microsoft has released update for Internet Explorer out of their regular update cycle. MS10-018 update fixes ten vulnerabilities (nine privately reported and one publicly disclosed). The update is categorized as critical and consumers get it easiest by using Microsoft Update service.

Summary of Microsoft security updates for March 2010 can be viewed here.

Tuesday, March 9, 2010

Pointer Related Vulnerability In Internet Explorer

Microsoft has published an advisory in which they state that they are investigating public reports of a vulnerability affecting Internet Explorer web browser versions 6 and 7. Microsoft states that Internet Explorer 8 version is not affected.

The vulnerability is caused by an invalid pointer reference being used within Internet Explorer. Under specific conditions it is possible to access invalid pointer after an object is deleted. By exploiting this vulnerability in specific way, Internet Explorer can be used to allow remote code execution.

People in Microsoft are aware of targeted attacks attempting to use the vulnerability. They state that they will continue to monitor the situation and take appropriate action to protect the customers.

The advisory can be found here.

Monday, March 1, 2010

Microsoft Investigating A New Internet Explorer Related Issue

Microsoft has published a blog entry in which they state that they are investigating issue that could allow an attacker to could allow an attacker to host a maliciously crafted web page and run arbitrary code if they could convince a user to visit the web page and then get them to press the F1 key in response to a pop up dialog box.

The issue in question involves the use of VBScript and Windows Help files in Internet Explorer. Windows Help files are included in a long list of what we refer to as “unsafe file types”. These are file types that are designed to invoke automatic actions during normal use of the files.

According to Microsoft, users running Windows 7, Windows Server 2008 R2, Windows Server 2008 and Windows Vista, are not affected by the issue.

There is not released a workaround solution for affected systems yet. Microsoft has promised to provide new information when it becomes available.

Thursday, February 4, 2010

New Vulnerability In Internet Explorer

Microsoft is investigating new publicly reported vulnerability in Internet Explorer. If a user is using a version of Internet Explorer that is not running in Protected Mode an attacker may be able to access files with an already known filename and location. The vulnerability exists due to content being forced to render incorrectly from local files in such a way that information can be exposed to malicious websites.

The versions not running in Protected Mode include Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service 4; Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4; and Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on supported editions of Windows XP Service Pack 2, Windows XP Service Pack 3, and Windows Server 2003 Service Pack 2. Protected Mode prevents exploitation of this vulnerability and is running by default for versions of Internet Explorer on Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008.

There's no patch released yet. More information including some workarounds can be read from the security advisory.

Saturday, January 23, 2010

Microsoft Patches Internet Explorer Vulnerability

Microsoft has fixed the Internet Explorer (IE) vulnerability I blogged about last week. The update MS10-002 patches also a few other IE vulnerabilities. More details can be read from the correspondent security bulletin.

Monday, November 23, 2009

Vulnerability In Internet Explorer

VUPEN security has reported about a vulnerability in Microsoft Internet Explorer web browser. The vulnerability could be exploited by an attacker to take over a vulnerable system. "This issue is caused due to a memory corruption error in the Microsoft HTML Viewer (mshtml.dll) when retrieving certain CSS/STYLE objects via the "getElementsByTagName()" method, which could allow attackers to crash an affected browser or execute arbitrary code by tricking a user into visiting a malicious web page", states VUPEN in their advisory.

Symantec verifies the vulnerability affects Internet Explorer versions 6 and 7.

At the moment, there's no patch for the vulnerability available yet. To minimize the chances of being affected by this issue, users of affected Internet Explorer versions are recommended to disable JavaScript support in the browser until Microsoft releases patch to the vulnerability.

More information:
http://isc.sans.org/diary.html?storyid=7624

EDIT:
Microsoft has released Security Advisory (977981) of the issue.