Posts Tagged ‘browser_bugs’

Exploit Published For Gaping (Patched) IE Hole

Posted by Jason in Software, Windows Vista, Windows XP on March 27th, 2007

If you haven’t applied the “critical” patch in ’s MS07-009 bulletin, now might be a good time to hit that download-and-install button. Detailed code for the vulnerability — discovered during HD Moore’s MOBB (month of browser bugs) project and fixed on Patch Tuesday in February — has surfaced on the , offering malware authors step-by-step instructions on how to launch PC takeover attacks.

The code takes aim at a remote code execution flaw in the ADODB.Connection control that is provided as part of the Data Objects. This is distributed in MDAC ( Data Access Components). (more…)