0-day attack targets Yahoo! Mail client
A zero day Yahoo! Mail vulnerability was exploited today that results in the execution of arbitrary code. The vulnerability lies within Yahoo's onload event handling, allowing an attacker to craft an email message that results in script execution when users read their Yahoo! Mail. In today's attack, a virus author utilized this exploit to run JavaScript that spams @yahoo.com and @yahoogroups.com recipients with a new virus (JS/Yamanner@MM – http://vil.mcafeesecurity.com/vil/content/v_139913.htm). Yahoo is reportedly working on a fix and blocking these messages.
Submit your own comments / message for this post