Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Microsoft Security Advisory 2488013 - New Internet Explorer vulnerability

A new vulnerability in Internet Explorer has been discovered. While exploits have not spread into the wild yet, users should be cautious in visiting any unusual and potentially malicious websites

Microsoft Security Advisory (2488013)
Vulnerability in Internet Explorer Could Allow Remote Code Execution
http://www.microsoft.com/technet/security/advisory/2488013.mspx

Additional Resources
http://www.f-secure.com/weblog/archives/00002080.html
http://isc.sans.edu/diary.html?storyid=10132
http://blogs.technet.com/b/msrc/archive/2010/12/22/microsoft-releases-security-advisory-2488013.aspx

QUOTE: This exploit has been discussed over the last day or so on full disclosure and a number of other sites. Metasploit already has a module available for it (just search for CSS & IE).  The issue manifests itself when a specially crafted web page is used and could result in remote code execution on the client.