Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New zero day vulnerability identified in all versions of IE
Cnet ^ | Apr 27, 2014 | Steven Musil

Posted on 04/27/2014 4:26:55 PM PDT by dayglored

A new zero day vulnerability that resides in all versions of Internet Explorer has been spotted in the wild, Microsoft confirmed late Saturday.

The vulnerability, which could allow remote code execution, is being used in "limited, targeted attacks," according to an advisory issued by Microsoft. While all versions of the web browser, IE 6 through 11, are affected by the vulnerability, attacks are currently targeting IE versions 9, 10 and 11, according to security firm Fire Eye, which first reported the flaw Friday.

The attack leverages a previously unknown "use after free" vulnerability -- data corruption that occurs after memory has been released -- and bypasses both Windows DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization) protections, according to Fire Eye.

An attack could be triggered by luring visitors to a specially crafted web page, Microsoft explained.

...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: aiee; gatesfoundation; ie; internetexplorer; microsoft; remotecodeexecution; stevenmusil; vulnerability; windowsxp; zeroday
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-8081-96 next last
This appears to be the first major flaw that WILL NOT GET FIXED FOR WINDOWS XP. And it is being actively exploited ALREADY.

Okay, XP die-hards, you were warned. Here it comes.

1 posted on 04/27/2014 4:26:55 PM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: dayglored; ShadowAce
Excerpt link (sorry, forgot it above)

http://www.cnet.com/news/new-zero-day-vulnerability-identified-in-all-versions-of-ie/

Tech ping?

2 posted on 04/27/2014 4:27:56 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
Further article text:
"The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated," Microsoft said. "The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer."

Microsoft said it is investigating the vulnerability and may issue an out-of-cycle security update to address the issue.

Fire Eye said the flaw was significant because it affects more than a quarter of the total browser market.

"Collectively, in 2013, the vulnerable versions of IE accounted for 26.25% of the browser market," Fire Eye said in its advisory.


3 posted on 04/27/2014 4:29:14 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

If its an IE problem what does XP have to do with it?


4 posted on 04/27/2014 4:35:24 PM PDT by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: driftdiver

M$.


5 posted on 04/27/2014 4:37:07 PM PDT by Paladin2
[ Post Reply | Private Reply | To 4 | View Replies]

To: Paladin2

In other words, nothing?


6 posted on 04/27/2014 4:37:34 PM PDT by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: driftdiver

Good question.

Does XP still receive IE updates however?

I wonder if it’s just static at this point?


7 posted on 04/27/2014 4:37:35 PM PDT by Cringing Negativism Network (http://www.census.gov/foreign-trade/balance/c5700.html#2013)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Cringing Negativism Network

The article says MS is looking to do an out of cycle update.

So yes, IE updates are separate from the OS. Remember when they were forced to unbundle them?


8 posted on 04/27/2014 4:38:45 PM PDT by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: driftdiver
The way their code is tied together and uses all sorts of propriety hooks who knows?

The only time I used IE was to get XP updates.

9 posted on 04/27/2014 4:39:35 PM PDT by Paladin2
[ Post Reply | Private Reply | To 6 | View Replies]

To: driftdiver
It's not an XP flaw, it's an IE flaw.

HOWEVER:

As far as I know, Microsoft discontinued support of old IE versions that run on XP, and does not back-port newer supported versions to XP. Therefore AFAIK there won't be any patches for the IE flaw, for any version that runs on XP.

If somebody can show that Microsoft will produce a patch for a version of IE that runs supported on XP, let me know please.

10 posted on 04/27/2014 4:40:30 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: driftdiver

I’m currently on Ubuntu (I have a copy of 8.1 but am currently still using Ubuntu IRL)

So this is not an actual XP issue then, it is an independent issue with the browser.


11 posted on 04/27/2014 4:41:49 PM PDT by Cringing Negativism Network (http://www.census.gov/foreign-trade/balance/c5700.html#2013)
[ Post Reply | Private Reply | To 8 | View Replies]

To: dayglored

This sounds like one more reason to never run your machine as an administrator useless you have a need. Most viruses can’t install with out admin rights.


12 posted on 04/27/2014 4:42:24 PM PDT by ThomasThomas (Some learn from others... The rest of them have to pee on the electric fence for themselves.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Paladin2
Ask any 100 XP users how to get IE updates WITHOUT using Windows Update service.

Best of luck with that. I'll bet you 99 of the 100 say, "WHUT?"

The 1 out of 100 is a corporate SysAdmin who has a Windows Update server.

13 posted on 04/27/2014 4:43:43 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: driftdiver

IE and the OS are in an incestuous relationship. The fix may require both the be patched.


14 posted on 04/27/2014 4:44:42 PM PDT by ImJustAnotherOkie (zerogottago)
[ Post Reply | Private Reply | To 4 | View Replies]

To: driftdiver
> In other words, nothing?

What this IE flaw has to do with XP is: the flaw will get a patch, for the newer, supported versions of IE. It WILL NOT get a patch for the older unsupported versions that run on XP.

AFAIK. If you know different, post a link to the Microsoft article that says it. Please!

15 posted on 04/27/2014 4:45:52 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: AdmSmith; AnonymousConservative; Berosus; bigheadfred; Bockscar; cardinal4; ColdOne; ...

Weird that this wasn’t discovered until such time as MS wants to panic its herd into W8.


16 posted on 04/27/2014 4:47:08 PM PDT by SunkenCiv (https://secure.freerepublic.com/donate/)
[ Post Reply | Private Reply | View Replies]

To: ImJustAnotherOkie
"The fix may require both the be patched."

Which software is more likely to have sloppy memory management?

17 posted on 04/27/2014 4:47:26 PM PDT by Paladin2
[ Post Reply | Private Reply | To 14 | View Replies]

To: driftdiver
Here's an article that says XP users will not get the update:

http://www.ibtimes.com/microsoft-hurries-fix-browser-after-hacker-attacks-no-fix-xp-users-1576931

"...PCs running Windows XP will not receive any updates fixing that bug when they are released..."

18 posted on 04/27/2014 4:50:49 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored
Microsoft has discontinued support for XP, Internet Explorer on XP, and Microsoft Defender.

If you're a Microsoft XP User, stop using Internet Explorer and switch to Google Chrome, FireFox, Safari or something other than IE.

As this is an EXPLOIT and not a Virus/Malware, the critical point is that the exploit is tied to IE.

For those of you with System Restore turned on make sure you have a System Restore point set, and a good backup of XP including the OS and your data files.

Stopping usage of IE will provide some protection for now but ultimately, XP is going to be breached world-wide and those of you running it will regret not upgrading.

19 posted on 04/27/2014 4:54:17 PM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 10 | View Replies]

To: driftdiver
> So yes, IE updates are separate from the OS.

Okay, you're on an XP system, and XP updates are unavailable. Please tell me how you get an update for your unsupported version of IE?

AFAIK, and this is the key: THE FACT THAT YOU'RE RUNNING XP MAKES YOU INELIGIBLE FOR ANY UPDATES, including IE updates.

If you know different, please post a link to the Microsoft page that says so. I'd sure like to have that link to give to my family and friends who are still running XP and will be calling me for help.

20 posted on 04/27/2014 4:55:30 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 8 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-8081-96 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson