also @ TechSpot: OCZ Vertex 450 Review

Unpatched Internet Explorer exploit hits the Web

By

On March 11, 2010, 4:33 PM

Israeli security researcher Moshe Ben Abu has published the exploit code of an unpatched Internet Explorer security hole. With the help of a McAfee blog post, Abu pinpointed the vulnerability in about 10 minutes. Microsoft warned on Tuesday that the bug could allow an attacker to take control of a computer, and advised users of IE 6 and 7 to install version 8 as soon as possible.

CNET asked Abu how dangerous the vulnerability is, and his response was in line with Microsoft's recommendation of updating to IE8. Abu also noted that the exploit is quite unstable, with about 60% to 70% success rate, and confirmed that it is critical to older builds of IE. Microsoft provided additional workarounds in its advisory for users who can't upgrade to the latest browser version.

Although information in McAfee's sped up the process, Abu said he would have found the vulnerability anyway. McAfee said the post in question did not contain enough information to directly lead anyone to the hole, but the firm's future blog posts will undergo "additional sanitization" to avoid giving exploit writers a starting point when hunting for exploit code.

No tags on this story

User Comments: 53

Got something to say? Post a comment
  1. give chrome a chance. you'll get use to it in a little span of time.

  2. Kind of pointless reporting it here, I mean most people who read these tech posts are probably using another browser.

  3. No ... I don't think that you are correct.

    We just don't hear about the Firefox holes.

    Hasn't Firefox had more security fixes for two years in a row now than IE has had?

    Do some research ... lots of Firefox security fixes occur that we never hear about ... blame the media, or start blaming Mozilla.

    I didn't stated in my post that other browsers (And why you said Firefox? You can't know exactly wich of those browsers is "leading" with number of exploits discovered) doesn't have security holes....look closely at my post and read careful. Still, I like here on TechSpot that they (mods and tech stuff) are not favorite any hardware or software, just writing news just like it should be, not on the way they like. So, If you are following news here on daily basis, you will see that there are a lot of other exploits, from other browsers, published here.

  4. I trust google chrome for best security

  5. I used to work for one of the UK's biggest companies in terms of employees and they only just upgraded to IE7 from IE6. Most businesses just see it as too much of an effort to upgrade software.

  6. @ slh28,

    Yes, in fact most of the comments here and in general when it's a new exploit in IE are from an individual using point of view, while most big corps use IE6/7 and have been doing that for ages, and they find it too hard and resources-demanding to upgrade to 8 not to mention changing to an alternative browser,

    hence is why IE is staying for a little longer...

  7. Well in corporate environment it's hard to go with alternatives.We also have to run IE7 because IE8 drops support for active desktop on WindowsXP and we use it to display our Intranet on all our computers desktop screens. If it was up to me I would switch everyone over but there is so much resistance to change it would take a security breach of some kind to force the issue.

  8. if IE is so full of holes, what would you expect from Windows ?

  9. lol...I didn't know people still used IE....I'm pretty sure everyone that knows anything about the internet knows that IE is horrible on the security side of things. I'm glad someone's gone out and shown publicly just how easy it is to break IE. google chrome ftw!

  10. Guest said:

    Why should people tolerate all the problems with IE when they have paid for a software that is suppose to be superior. Seems that Microsoft creates products with holes to try and force people to upgrade their products. People are paying for the right to be test subjects.

    People never have and most likely never will pay for IE. They pay for Windows, and IE just happens to be the browser loaded with Windows. In the European Union, they can actually install a different browser by default thanks to the ballot screen.

    At any rate, it is not as if Microsoft purposefully leaves holes in older products and is able to have people find them at a time that coincides with the release of a newer product.

  11. Sadly I still have to drag out IE at work since there are a good chunk of sites we need to access that wont work in anything but IE or are just extremely unstable in anything but IE. I have sent emails to most of the site managers saying they really need to make their site compatibly with the 4 other major browsers, or at least firefox....but they don't

  12. Sadly I still have to use IE for a few sites we access at work, like isqft and other builders exchange sites, gotta see what the competition has u know .

  13. Another reason not to use Internet Explorer. (As if we needed one.)

  14. DryIce said:

    Another reason not to use Internet Explorer. (As if we needed one.)

    +1 agreed.

    only reason to use this browser is for web based apps only supporting IE

  15. Relic said:

    Guest said:

    Oh, so nothing new?

    Heh ya, first thing that came to mind when I read the headline too.

    LOL, same here ...

    i use IE8 on one of my Windows install, yet i prefer to use Chrome & Firefox, i just hate it when some sites doesn't display same on the browsers.

    cheers!

  16. It still boggles my mind at how slow and insecure IE is, but what really blows my mind is the fact that SO many people are still using it! Why can't MS just start completely from scratch and create a solid browser?

  17. I wonder why IE6 does not die or become obsolete as it has been heavily criticized

  18. Hmmm, time to upgrade to IE8 on my Windows XP build!

  19. i love firefox

  20. Internet Explorer has a good performance and I don't agree that the only way is to migrate to other web browsers. Why not using Internet Explorer 8 and this software is pretty good.

    Just upgrade your browsers do that you will not left behind with the pace of the technology right now.

  21. After all these years, MS is still patching holes in IE; they are just too numerous! There are problems with the other browsers, true, but IE ... is anyone really surprised that 'yet another hole' has been found.

    I only use IE for sites that won't display correctly in Opera (my 1st choice) or Firefox.

  22. MS needs to can IE8 and start from the ground up with a new browser imo.

  23. Insanely

    Exploitable

    Just use Firefox, Chrome, Opera or Safari. Please.

  24. who's using IE?

    everybody should use chrome or opera!

    atleast i expect that all of the techspot readers are not using IE!

  25. Goes without saying these days, but if you use Microsoft stay up to date on updates and patches. While no guarentee, its your best bet without switching OS's.

Recently commented stories

Post a new comment

Social Login & Guest Posting TechSpot Members
Login here or sign up for free,
it takes about a minute.
Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.
TechSpot on:

Subscribe to TechSpot

Get free exclusive content, learn about new features and breaking tech news.