Microsoft Warns of New Internet Explorer Zero-Day Attack

In a security advisory released Wednesday, Microsoft warned users of Internet Explorer vulnerability that could allow remote code execution by hackers. The security breach can be accessed on XP, Vista, and Windows 7 systems running Internet Explorer 6, 7, and 8.

According to the advisory, "The vulnerability exists due to an invalid flag reference within Internet Explorer. It is possible under certain conditions for the invalid flag reference to be accessed after an object is deleted. In a specially crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution."

In the event the vulnerability were exploited, hackers would be able to hijack a target's computer to access a network system and install additional malware.

Microsoft stated that it is working on a fix and has suggested a workaround for the possible breach, which can be found here.  

In a blog entry discussing to the vulnerability, Jerry Bryant, group manager of response communications in the Microsoft Trustworthy Computing Group, said that Microsoft acted quickly when the malicious code had been pinpointed to a single Web site. "When a Web site is discovered to host malicious software, we work through legal channels to take the site down," wrote Bryant. "These kinds of attempts to exploit systems and the people using technology are the activity of criminals. Microsoft takes this very seriously and where possible, we will take legal action against those responsible."

In addition to the workaround provided by Microsoft, Bryant suggested that all applicable software be up-to-date and that firewalls, anti-spyware, and anti-virus programs be up and running.  

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured

  • stacks of science worksheets with scientific icons

    Kognity Intros Blended Learning Resources for Science Instruction

    Science education platform Kognity has launched a suite of blended learning resources for its four science courses: Biology, Chemistry, Physics, and Earth & Space Science.

  • Red alert symbols and email icons floating in a dark digital space

    Report: Cyber Attackers Are Fully Embracing AI

    According to Google Cloud's 2026 Cybersecurity Forecast, AI will become standard for both cyber attackers and defenders, with threats expanding to virtualization systems, blockchain networks, and nation-state operations.

  • cloud with binary code and technology imagery

    Hybrid and AI Expansion Outpacing Cloud Security

    A survey from the Cloud Security Alliance and Tenable finds that rapid adoption of hybrid, multi-cloud and AI systems is outpacing the security measures meant to protect them, leaving organizations exposed to preventable breaches and identity-related risks.

  • rear view of students in a classroom

    Edthena Launches AI-Powered Classroom Observation Tool

    Professional learning platform Edthena has introduced Observation Copilot, an AI tool for principals designed to streamline the process of writing up framework-aligned teacher feedback from classroom observation notes.