Yesterday, it was reported that an Internet Explorer zero-day threat was actively being exploited in the wild. We did a quick analysis and have some interesting findings. The exploit contains four parts: Exploit.html. First-stage exploiting web page (initialize variables and load the .swf file). Moh2010.swf. Encrypted SWF using DoSWF, it contains shellcode and heap spray Read more…
Tags: 0day vulnerability, Internet Explorer, ROP, Zero-Day
On June 1, McAfee Labs discovered a new Microsoft Internet Explorer zero-day attack that is active in the wild and exploits a use-after-free vulnerability. We have successfully reproduced it with the latest IE8 and Windows 7. We have confirmed it’s a zero day and have been working with the Microsoft security team for their solutions. Read more…
Tags: ASLR, exploit, Internet Explorer, java, msvcr71.dll, ROP, use after free, vulnerability, Zero-Day
Microsoft delivered 10 security updates yesterday to patch a record-tying 34 vulnerabilities in Windows, Internet Explorer, Office and SharePoint. Microsoft labeled three as “critical” – because they allowed attackers to remotely install malware on victim machines – two address issues in Windows and the third, tackles Internet Explorer (IE). The IE update fixes vulnerabilities that Read more…
Tags: Endpoint Protection, Internet Explorer, Patch Tuesday, SharePoint, vulnerability, Windows 7
Posts tagged under Internet Explorer