Register | Login

Older versions of Internet Explorer are under attack. Microsoft warned Tuesday afternoon that cybercriminals are actively exploiting a security vulnerability that lets attackers execute malicious code from remote locations.

Microsoft`s internal investigation reveals that the latest version of the browser, Internet Explorer 8, is not affected. Likewise, Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4 is not affected.

Here`s a quick list of affected versions for IT administrators looking to implement a workaround to mitigate the risk: Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6 and Internet Explorer 7.

"In addition to Microsoft`s Patch Tuesday updates today, the company also issued an advisory for a new zero-day vulnerability affecting Internet Explorer," said Josh Talbot, security intelligence manager for Symantec Security Response. "Symantec has observed exploitation of this vulnerability in the wild and has created Trojan.Malscript!html and JS.Downloader detection to mitigate this attack."

The Root of the Problem

Microsoft said the vulnerability exists due to an invalid pointer reference being used within Internet Explorer. Under certain conditions, it`s possible for the invalid pointer to be accessed after an object is deleted, according to a March 9 Microsoft security advisory. In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution.

"At this time, we are aware of targeted attacks attempting to use this vulnerability. We will continue to monitor the threat environment and update this advisory if this situation changes," Microsoft said. "On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs."

Mitigating Factors

IT administrators can take heart in the mitigating factors that may protect their...

Who Voted for this Story


Username:

Password:

Remember: