SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Technology

Unpatched IE7 exploit imperils millions of computers

Unpatched IE7 exploit imperils millions of computers

By:  Jeremy Kirk  On: 11 Dec 2008 For: IDG News Service (London Bureau)(NA) Creator

Vulnerability affects computers running IE7 on Windows XP regardless of the service pack version, Windows Server 2003 running Service Pack 1 or 2, Windows Vista and Windows Vista with Service Pack 1 as well as Windows Server 2008

Chinese security researchers mistakenly released the code needed to hack a PC by exploiting an unpatched vulnerability in Microsoft's Internet Explorer 7 browser, potentially putting millions of computer users at risk -- but it appears some hackers already knew how to exploit the flaw.

At one point, the code was traded for as much as US$15,000 on the underground criminal markets, according to iDefense, the computer security branch of VeriSign, citing a blog post from the Chinese team.

The problem in Internet Explorer 7 means a computer could be infected with malicious software merely by visiting a Web site, one of the most dangerous computer security scenarios. It affects computers running IE7 on Windows XP regardless of the service pack version, Windows Server 2003 running Service Pack 1 or 2, Windows Vista and Windows Vista with Service Pack 1 as well as Windows Server 2008.

Microsoft has acknowledged the issue but has not indicated when it will release a patch. Earlier, a release of several patches by the company missed a critical bug.

The vulnerability was first revealed earlier this week by the Chinese security team "knownsec." Knownsec said on Tuesday they mistakenly released exploit code thinking that the problem was already patched, iDefense said.

"This is our mistake," knownsec said in a Chinese-language research note.

That mistake could mean that more hackers will try to build Web sites in order to compromise users PCs since the exploit code is more freely floating around on the Internet. However, other information indicates that hackers already knew how it worked before the release. According to knownsec, a rumor surfaced earlier in the year about a bug in Internet Explorer, iDefense wrote.

Information on the vulnerability was allegedly sold in November on the underground back market for US$15,000. Earlier this month, the exploit was sold second or third hand for $650, said iDefense, citing knownsec.

The sale of vulnerabilities has long been a profitable practice for hackers.

Eventually, someone developed a Trojan horse program -- one that appears harmless but is actually malicious -- that is designed to steal information related to Chinese-language PC games, a popular target for hackers.

Now, other Web sites are being built that incorporate the exploit. Hackers then usually try to get people to visit those sites through spam or unsolicited instant messages.


Sign up for our Newsletters












Print |  Views: 1307   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Jeremy Kirk Jeremy Kirk is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Microsoft gets short on security update
Microsoft gets short on security updateIt's that time of the month again as Microsoft gets ready to issue November's monthly security update, which fixes known flaws in the company's Windows operating system. Don't be surprised, however, if the list of security updates is unusually short this time around.
Researchers reveal another Firefox flaw
Researchers reveal another Firefox flawMozilla's challenger to Microsoft's Internet Explorer faces a growing list of problems in the way it passes URLs to other applications. Browser users wait for an automatic update
Disable Windows ActiveX control for safety, says Microsoft
Disable Windows ActiveX control for safety, says MicrosoftMicrosoft is investigating reports of a vulnerability in a Windows ActiveX control that could allow an attacker to remotely take control of a computer, according to an advisory. One security company rated the vulnerability critical, while Microsoft said it allowed only limited attacks.
Protect yourself from the Internet Explorer bug
avg technologies nv of amsterdam announced this week version 8.0 of its security software has blocked 5,000 hacking attempts by miscreants exploiting a bug in the data binding features of microsoft internet explorer.avg version 8.0 includes rea
blog comments powered by Disqus