Internet Storm Center’s always informative Diary has some good information.
At the urging of Handler Extraordinaire Kyle Haugsness, I tested the sploit on a box with software-based DEP and DropMyRights… here are the results:
Software-based DEP protecting core Windows programs: sploit worked
Software-based DEP protecting all programs: sploit worked
DropMyRights, config’ed to allow IE to run (weakest form of DropMyRights protection): sploit worked
Active Scripting Disabled: sploit failed
So, go with the last one, if you are concerned. By the way, you should be concerned.
It didn’t take long for the exploits to appear for that IE vulnerability. One has been making the rounds that pops the calculator up (no, I’m not going to point you to the PoC code, it is easy enough to find if you read any of the standard mailing lists), but it is a relatively trivial mod to turn that into something more destructive. For that reason, SANS is raising Infocon to yellow for the next 24 hours.
Microsoft recommends you turn Active Scripting OFF to protect against this vulnerability.
Yah I know, yet another reason to dump Internet Explorer and grab Firefox, not that anyone reading this site would be using Internet Exploder..
The code is along the lines of:
You can find the Bleeding Snort rule for the IE Exploit here.
“We’re still investigating, but we have confirmed this vulnerability and I am writing a Microsoft Security Advisory on this,” writes Lennart Wistrand, security program manager with the Microsoft Security Response Center, in a blog posting. “We will address it in a security update.”
There is also a 3rd party fix for this from eEye.
- XcodeGhost iOS Trojan Infected Over 4000 Apps
- WhatsApp Web vCard Vulnerability Exposed 200M Users
- Mimikatz – Gather Windows Credentials
- New Critical MEGApatch fixes 10 Vulnerabilities in Internet Explorer
- Microsoft Confirms Internet Explorer 0-Day
- Microsoft Rushes Out ‘Fix It’ For Internet Explorer 0-day Exploit
Most Read in Exploits/Vulnerabilities:
- Learn to use Metasploit – Tutorials, Docs & Videos - 231,774 views
- AJAX: Is your application secure enough? - 119,685 views
- eEye Launches 0-Day Exploit Tracker - 85,281 views