Zero-Day Exploit Targeting All Microsoft Internet Explorer Web Browsers

Advertisement

FireEye Research Labs has found a Zero-Day Exploit that affects Microsoft Internet Explorer (IE) web browser versions 6, 7, 8, 9, 10 and 11. Persons using Microsoft Windows XP are more vulnerable to this threat, because Microsoft has stopped providing support and updates for this 13 year-old operating system.

Zero-Day Exploit Targeting All Microsoft Internet Explorer Web Browsers
Advertisement

Updated May 2, 2014 - Microsoft has fixed the vulnerability in all versions of Internet Explorer, even on Windows XP, although they have stopped supporting it. Click here to download the fix or patch for your version of Internet Explorer, or click here to download it from Microsoft Windows Update.

This is what Microsoft has to say about this vulnerability:

The vulnerability is a remote code execution vulnerability. The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated.

The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.

On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.

For more information about this exploit, please click here.

Check the comment section below for additional information, share what you know, or ask a question about this article by leaving a comment below. And, to quickly find answers to your questions, use our search Search engine.

Note: Some of the information in samples on this website may have been impersonated or spoofed.
Would you share this article with others?  +

DonateHelp maintain Online Threat Alerts (OTA).

Comments, Questions, Answers, or Reviews

Comments (Total: 1)

To protect your privacy, please do not post or remove sensitive information in or from your comments, questions, or reviews. NB: We will use your IP address to display your approximate location to other users. That location is not enough to find you.

Your comment, answer, or review will be set as anonymous because you are not signed in. An anonymous comment, answer, or review cannot be edited or deleted, therefore, review it carefully before posting. Sign-in.

The comments, reviews or answers below do not necessarily reflect the views of Online Threat Alerts (OTA).

  • May 2, 2014 at 11:14 AM by info

    Microsoft has fixed the vulnerability in all versions of Internet Explorer, even on Windows XP, although they have stopped supporting it.

    <a href="http://technet.microsoft.com/en-us/library/security/ms14-021.aspx" target="_blank">Click here</a> to download the fix or patch for your version of Internet Explorer, or <a href="http://go.microsoft.com/fwlink/?LinkId=21130" target="_blank">click here</a> to download it from Microsoft Windows update.

Comments Show More Comments (0)

Write Your Comment, Question, Answer, or Review

Recommendation / Advertisement
Zero-Day Exploit Targeting All Microsoft Internet Explorer Web Browsers