Remote-Code Vulnerability Being Exploited in IE 6 and 7
March 10th, 2010
Older versions of Internet Explorer are under attack. Microsoft
warned Tuesday afternoon that cybercriminals are actively exploiting a security vulnerability that lets attackers execute malicious code from remote locations.
Microsoft’s internal investigation reveals that the latest version of the browser, Internet Explorer 8, is not affected. Likewise, Internet Explorer 5.01 Service Pack 4 on Microsoft Windows
2000 Service Pack 4 is not affected.
Here’s a quick list of affected versions for IT administrators looking to implement a workaround to mitigate the risk: Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6 and Internet Explorer 7.
“In addition to Microsoft’s Patch Tuesday updates today, the company also issued an advisory for a new zero-day vulnerability affecting Internet Explorer,” said Josh Talbot, security intelligence manager for Symantec Security Response. “Symantec has observed exploitation of this vulnerability in the wild and has created Trojan.Malscript!html and JS.Downloader detection to mitigate this attack.”
Read the rest of the story on NewsFactor.
Entry Filed under: Hot off the Press






Leave a Comment
Some HTML allowed:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
Trackback this post | Subscribe to the comments via RSS Feed