SlideShare a Scribd company logo
By MatthewSparkes
4:42PM BST 22 May 2014
A flawinMicrosoft'sInternetExplorerwhichleavesusersvulnerabletohackershasnot beenfixed,
despite itsdiscoverergivingthe companysix monthsgrace todo so before publishingdetails.
The flaw"allowsremote attackerstoexecute arbitrarycode"onvulnerable,olderversionsof IEsuchas
8, says the ZeroDay Initiative site,whichoffersrewardsforfindingflawsincommercialsoftware.Itwas
originallydiscoveredbyPeterVanEeckhoutte,alsoknownas"corelanc0d3r".
User interactionisrequiredtoexploitthe hole,inthatthe victimwouldhave toopenamalicious
website orfile.Althoughthe software hasnow beenreplaced,itstill accountsforaround20 percentof
internettrafficaccordingtostatisticsfromNetApplications.
The flawwas firstdisclosedtoMicrosoftinNovemberlastyear,andthe site usuallygives180 daysfor a
fix tobe appliedbeforeitispubliclydisclosed.ByFebruary,Microsofthadconfirmedthatithad been
able to replicate the problem,buthadnotfixedit.
ZeroDay Initiative heardnoindicationthatitwouldbe fixed,soextendedthe usual secrecyperiod,
informedMicrosoftthatitwas goingto go aheadwithpublication,andeventuallyreleasedthe
informationlate lastnight

More Related Content

PPTX
Wirelurker
PPTX
Regin
PDF
Malicious malware breaches - eScan
PDF
NewsByte Mumbai October 2017
PDF
Briskinfosec - Threatsploit Report Augest 2021- Cyber security updates
PPTX
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
PPT
Sahilmod 120315100301-phpapp01
RTF
Bash software bug could be bigger threat than heartbleed, experts warn
Wirelurker
Regin
Malicious malware breaches - eScan
NewsByte Mumbai October 2017
Briskinfosec - Threatsploit Report Augest 2021- Cyber security updates
Open Source Insight: CVE–2017-9805, Equifax Breach & Wacky Open Source Licenses
Sahilmod 120315100301-phpapp01
Bash software bug could be bigger threat than heartbleed, experts warn

What's hot (17)

PPTX
Open Source Insight: Top Picks for Black Hat, GDPR & Open Source Webinar, ...
PPTX
Open Source Insight: Happy Birthday Open Source and Application Security for ...
PPTX
Anti virus slide show presentation
PPT
49871001
PPTX
Top 15 security predictions for 2017
PPT
Current Emerging Threats
PPTX
Null hyderabad - October Newsbytes
PDF
Null mumbai news bytes by Rahul Tulaskar
PPTX
NewsBytes - Nullhyd
PPTX
New wave of attacks in Ukraine 2016
PDF
Null mumbai Session on ransomware by_Aditya Jamkhande
PPTX
Security News Bytes March 2020
PDF
Patches Arrren't Just for Pirates
PDF
Trojan horseofbyod2
PPT
Ibm risk management-30min
PDF
Top 6-Security-Threats-on-iOS
Open Source Insight: Top Picks for Black Hat, GDPR & Open Source Webinar, ...
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Anti virus slide show presentation
49871001
Top 15 security predictions for 2017
Current Emerging Threats
Null hyderabad - October Newsbytes
Null mumbai news bytes by Rahul Tulaskar
NewsBytes - Nullhyd
New wave of attacks in Ukraine 2016
Null mumbai Session on ransomware by_Aditya Jamkhande
Security News Bytes March 2020
Patches Arrren't Just for Pirates
Trojan horseofbyod2
Ibm risk management-30min
Top 6-Security-Threats-on-iOS
Ad

Similar to A flaw in Microsoft's Internet Explorer (20)

PDF
Bot software spreads, causes new worries
PDF
Security News bytes October 2013
PPS
Conficker
PPTX
Open Source Insight: NotPetya Strikes, Patching Is Vital for Risk Management
PPTX
News Bytes - December 2015
PDF
Briskinfosec - Threatsploit Report Augest 2021- Cyber security updates
PDF
Global Cybersecurity Threat Escalates_ Over 2,000 Palo Alto Devices Compromis...
PPTX
Newsbytes_NULLHYD_Dec
PDF
We explain the security flaw that's freaking out the internet
PPTX
News bytes Sept-2011
PPTX
Open Source Insight: Artifex Ruling, NY Cybersecurity Regs, PATCH Act, & Wan...
PPTX
cyber attacks in May , breaches in May
PDF
Ce hv8 module 17 evading ids, firewalls, and honeypots
PDF
PDF
Malware freak show
PDF
Developer is an attack vector
DOCX
Hamza
PDF
INSECURE Magazine - 35
PPTX
beware of Thing Bot
PPT
Group1 First Periodical Exam
Bot software spreads, causes new worries
Security News bytes October 2013
Conficker
Open Source Insight: NotPetya Strikes, Patching Is Vital for Risk Management
News Bytes - December 2015
Briskinfosec - Threatsploit Report Augest 2021- Cyber security updates
Global Cybersecurity Threat Escalates_ Over 2,000 Palo Alto Devices Compromis...
Newsbytes_NULLHYD_Dec
We explain the security flaw that's freaking out the internet
News bytes Sept-2011
Open Source Insight: Artifex Ruling, NY Cybersecurity Regs, PATCH Act, & Wan...
cyber attacks in May , breaches in May
Ce hv8 module 17 evading ids, firewalls, and honeypots
Malware freak show
Developer is an attack vector
Hamza
INSECURE Magazine - 35
beware of Thing Bot
Group1 First Periodical Exam
Ad

More from Michael Holt (13)

RTF
NSA, GCHQ, Five, Nine and Fourteen Eyes White Paper on Cybersecurity Exploit ...
RTF
NSA, GCHQ, Five, Nine, Fourteen Eye tactics and techniques
RTF
Icreach — nsa's secret google like search engine for metadata analysis
DOCX
Google never killed authorship entirely, some of the code still remains being...
RTF
Federal CyberSecurity Whistleblower on Analytics trackers and Backdoor Access
DOCX
Veterans Administration Hacked by foreign orgs, security needs standardization
DOC
Letter of Recommendation - Holt(1)
PDF
Merit Systems Protection Board Docket Number SF-0752-11-0427-I-1
PDF
Ron Wyden
DOCX
NSA's Secret Google-Like Search Engine for Metadata Analysis
DOCX
Beacons
RTF
Analytics Trackers
RTF
Andrzejewski, Barbara
NSA, GCHQ, Five, Nine and Fourteen Eyes White Paper on Cybersecurity Exploit ...
NSA, GCHQ, Five, Nine, Fourteen Eye tactics and techniques
Icreach — nsa's secret google like search engine for metadata analysis
Google never killed authorship entirely, some of the code still remains being...
Federal CyberSecurity Whistleblower on Analytics trackers and Backdoor Access
Veterans Administration Hacked by foreign orgs, security needs standardization
Letter of Recommendation - Holt(1)
Merit Systems Protection Board Docket Number SF-0752-11-0427-I-1
Ron Wyden
NSA's Secret Google-Like Search Engine for Metadata Analysis
Beacons
Analytics Trackers
Andrzejewski, Barbara

A flaw in Microsoft's Internet Explorer

  • 1. By MatthewSparkes 4:42PM BST 22 May 2014 A flawinMicrosoft'sInternetExplorerwhichleavesusersvulnerabletohackershasnot beenfixed, despite itsdiscoverergivingthe companysix monthsgrace todo so before publishingdetails. The flaw"allowsremote attackerstoexecute arbitrarycode"onvulnerable,olderversionsof IEsuchas 8, says the ZeroDay Initiative site,whichoffersrewardsforfindingflawsincommercialsoftware.Itwas originallydiscoveredbyPeterVanEeckhoutte,alsoknownas"corelanc0d3r". User interactionisrequiredtoexploitthe hole,inthatthe victimwouldhave toopenamalicious website orfile.Althoughthe software hasnow beenreplaced,itstill accountsforaround20 percentof internettrafficaccordingtostatisticsfromNetApplications. The flawwas firstdisclosedtoMicrosoftinNovemberlastyear,andthe site usuallygives180 daysfor a fix tobe appliedbeforeitispubliclydisclosed.ByFebruary,Microsofthadconfirmedthatithad been able to replicate the problem,buthadnotfixedit. ZeroDay Initiative heardnoindicationthatitwouldbe fixed,soextendedthe usual secrecyperiod, informedMicrosoftthatitwas goingto go aheadwithpublication,andeventuallyreleasedthe informationlate lastnight