Exploit Published For Gaping (Patched) IE Hole

Topics Software, Windows Vista, Windows XP on March 27th, 2007

If you haven’t applied the “critical” patch in ’s MS07-009 bulletin, now might be a good time to hit that download-and-install button. Detailed code for the vulnerability — discovered during HD Moore’s MOBB (month of browser bugs) project and fixed on Patch Tuesday in February — has surfaced on the , offering malware authors step-by-step instructions on how to launch PC takeover attacks.

The code takes aim at a remote code execution flaw in the ADODB.Connection control that is provided as part of the Data Objects. This is distributed in MDAC ( Data Access Components).

In the MS07-009 bulletin, warns: An attacker could host a specially crafted Web site that is designed to this vulnerability through Explorer and then persuade a user to view the Web site. This can also include Web sites that accept user-provided content or advertisements, Web sites that host user-provided content or advertisements, and compromised Web sites. These Web sites could contain specially crafted content that could this vulnerability… It could also be possible to display specially crafted Web content by using banner advertisements or by using other methods to deliver Web content to affected systems.

The publication of this has caught the attention of the security research community because this type of vulnerability has been very popular with malicious attacks in the past.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • del.icio.us
  • StumbleUpon
  • Facebook
  • Google
  • Furl
  • Live
  • MisterWong.DE
  • NewsVine
  • Reddit
  • Slashdot
  • Technorati
  • YahooMyWeb
  • BlinkList
  • description
  • Fark
  • Netvouz
  • Spurl
  • MisterWong
  • Webnews.de
  • e-mail

Tags:, , , , , , , , , , ,

Related posts

Leave a Reply