internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Hackers Target IE 7 Browser Again
Uninitialized Memory Corruption Vulnerability Under Attack Again
Richard Adhikari

Users who failed to patch their computers after Microsoft released its monthly Patch Tuesday update last week could be in trouble — an Internet Explorer (IE) browser vulnerability for which the patch was sent out is under attack again.

This IE patch released last week, for an "Uninitialized Memory Corruption" vulnerability, was rated critical by Microsoft. Also known as CVE-2009-0075, the vulnerability stems from how IE deals with objects that have been deleted.

An attack discovered yesterday targeted that vulnerability again. "Malware crooks were quick to develop a working exploit for the vulnerability in Internet Explorer 7, which was part of the February Microsoft patch release," said Raul Mohandas, in antivirus vendor McAfee's Avert Labs blog.

Hackers can exploit the Uninitialized Memory Corruption vulnerability by building a Web page that remotely executes code when it is visited.

Mohandas' blog posting said the latest attack is launched through a Microsoft Word document that contains an embedded ActiveX control. The ActiveX control connects to a Web site hosting the attack when it is opened.

This method is similar to the follow up to the zero-day attack on IE 7 in December that forced Microsoft to issue an out of band patch, Mohandas said in the blog.

Craig Schmugar, senior threat researcher at McAfee, told InternetNews.com he is not sure whether or not hackers had reverse engineered the patch issued last week, although there is a good possibility that this is the case. "There's the concept of Exploit Wednesday on the heels of Patch Tuesday where, in the course of providing a fix, you provide an opportunity for the bad guys to attack people who can't patch their systems that quickly," he added.

However, Bojan Zdmja, writing on the Internet Storm Center's (ISC) Web site, appears convinced that the hacker reverse engineered the patch. The ISC was created in 2001 to provide free analysis and warning services to Internet users and organizations.

Users' troubles with their IE browser may not be over yet. Schmugar warned that, although the attacker is using a Word document now, nothing prevents the exploit from being used in a drive-by attack, where a tainted Web site automatically downloads malware onto visitors' sites. "We can, unfortunately, expect that this will happen very soon," he wrote on the ISC's Web site.

IE has been hit by a series of vulnerabilities in the past few months because the browser is a tempting target. "Internet Explorer vulnerabilities are more likely to yield exploit code after a patch because there are more tools around to create a new exploit," Schmugar said.

"Install the MS09-002 patch, which was sent out last week, immediately."

News courtesy of internetnews.com

February 18, 2009

Download Internet Explorer Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. Uninitialized Memory Corruption Vulnerability Under Attack Again


Additional Articles:

  • Internet Explorer 7: Ready for Public Consumption
  • Gates Mixes It Up with IE, Atlas
  • Microsoft Plans Patch for IE Hole
  • New IE Exploits Create Security Scramble
  • IE 7 Is 'Layout Complete'
  • IE7 Beta 2 Out of Preview
  • Microsoft to Take Third Shot at IE 7 Beta
  • IE, Firefox Users at Risk from New Flaws
  • Third IE 7 Beta Has Layout Changes
  • First Release Candidate for IE 7 Hits
  • Report: IE 7 Has the Best Anti-Phishing Filter
  • Microsoft Planning Life After IE7
  • IE 7 Is Out the Door
  • IE 7's First Security Hole
  • Another Bug Bites IE7
  • Is IE 7 Limiting Remote Access SSL-VPNs?
  • IE 7 Tops 100M Download Mark
  • Internet Explorer at Zero-Day Risk
  • Microsoft Issues IE Security Alert
  • Microsoft to Roll Back the Clock on ActiveX
  • Internet Explorer 8 Passes the 'Acid2' Test
  • Internet Explorer 8 Tries New Compatibility Solution
  • IE8 Beta Soon But Few Details Yet
  • Microsoft Admits IE Still Flawed
  • Microsoft Set to Fix IE Zero Day Flaw
  • Microsoft Patches IE, But Security Issues Remain
  • EU to Insist Windows Includes Rival Web Browsers


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs