Microsoft Warns of New Internet Explorer Zero-Day Attack

In a security advisory released Wednesday, Microsoft warned users of Internet Explorer vulnerability that could allow remote code execution by hackers. The security breach can be accessed on XP, Vista, and Windows 7 systems running Internet Explorer 6, 7, and 8.

According to the advisory, "The vulnerability exists due to an invalid flag reference within Internet Explorer. It is possible under certain conditions for the invalid flag reference to be accessed after an object is deleted. In a specially crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution."

In the event the vulnerability were exploited, hackers would be able to hijack a target's computer to access a network system and install additional malware.

Microsoft stated that it is working on a fix and has suggested a workaround for the possible breach, which can be found here.  

In a blog entry discussing to the vulnerability, Jerry Bryant, group manager of response communications in the Microsoft Trustworthy Computing Group, said that Microsoft acted quickly when the malicious code had been pinpointed to a single Web site. "When a Web site is discovered to host malicious software, we work through legal channels to take the site down," wrote Bryant. "These kinds of attempts to exploit systems and the people using technology are the activity of criminals. Microsoft takes this very seriously and where possible, we will take legal action against those responsible."

In addition to the workaround provided by Microsoft, Bryant suggested that all applicable software be up-to-date and that firewalls, anti-spyware, and anti-virus programs be up and running.  

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured

  • ClassVR headsets

    Avantis Education Launches New Headsets for ClassVR Solution

    Avantis Education recently introduced two new headsets for its flagship educational VR/AR solution, ClassVR. According to a news release, the Xcelerate and Xplorer headsets expand the company’s offerings into higher education while continuing to meet the evolving needs of K–12 users.

  • Abstract AI circuit board pattern

    Nonprofit LawZero to Work Toward Safer, Truthful AI

    Turing Award-winning AI researcher Yoshua Bengio has launched LawZero, a nonprofit aimed at developing AI systems that prioritize safety and truthfulness over autonomy.

  • blue AI cloud connected to circuit lines, a server stack, and a shield with a padlock icon

    Report: AI Security Controls Lag Behind Adoption of AI Cloud Services

    According to a recent report from cybersecurity firm Wiz, nearly nine out of 10 organizations are already using AI services in the cloud — but fewer than one in seven have implemented AI-specific security controls.

  • magnifying glass highlighting a human profile silhouette, set over a collage of framed icons including landscapes, charts, and education symbols

    New AI Detector Identifies AI-Generated Multimedia Content

    Amazon Web Services and DeepBrain AI have launched AI Detector, an enterprise-grade solution designed to identify and manage AI-generated content across multiple media types. The collaboration targets organizations in government, finance, media, law, and education sectors that need to validate content authenticity at scale.