Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

C2 provides technology services and consultation to businesses and individuals.

T (818) 584 6021
Email: [email protected]

C2 Technology Partners, Inc.
26500 Agoura Rd, Ste 102-576, Calabasas, CA 91302

Open in Google Maps
QUESTIONS? CALL: 818-584-6021
  • HOME
  • BLOG
  • SERVICES
    • Encryption
    • Backups
  • ABOUT
    • SMS Opt-In Form
    • Terms and Conditions
    • Privacy Policy
FREECONSULT
Tuesday, 12 November 2013 / Published in Woo on Tech

Another IE Zero Day Exploit in the Wild

Microsoft Zero-day Warning

It’s nice that Microsoft can keep guys like me busy. Luckily, exploitation of their latest zero-day weakness seems to be limited (so far) to an advanced persistent threat (APT) attack targeting users of a specific national and international security policy website. This particular exploit is being delivered in a traditional “drive-by” attack when users of the English-version of Internet Explorer (specifically IE 7 and 8 on Windows XP, and IE 8 on Windows 7) visit this website. What distinguishes it from past threats is this malware’s ability to write malicious code directly to memory and then execute without writing to disk, a technique that makes detection and remediation much more difficult.

Microsoft intends to release a patch for this vulnerability as early as tomorrow (Nov 12). This is very fast for someone like Microsoft, and may be an indication of how serious this particular vulnerability might be.

What this means for you:

Though the exploit seems to be narrowly targeted at the moment, security researches say it wouldn’t be hard to manipulate the existing attack software to affect all versions of IE from 7 through 10, and any language in which IE is distributed. Assuming you have the leeway to do so, I still recommend using another browser like Chrome or Firefox, which still have a better track record when it comes to catching and patching weaknesses like the above. If you are required to use IE, make sure Windows Update is functional, and that you apply all critical and important updates as they are downloaded to your computer. Larger companies may control how frequently Windows Updates are applied in their enterprise, but don’t be afraid to ask your resident IT representative if they are taking steps to keep Internet Explorer safe for your use.

  • Tweet
Tagged under: advanced persistent threat, browser, chrome, firefox, internet explorer, microsoft, security, zero day

What you can read next

T-Mobile hacked
T-Mobile, Scottstrade join the hacked parade
Microsoft zero-day warning
New IE zero-day surfaces
Rogue Server
Is Your Webserver a Double-agent?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Remote Work Technology Setup: What Matters for Professional Services Firms

    Remote Work Technology Setup: What Matters for Professional Services Firms

    Remote work is no longer a temporary arrangemen...
  • Backup

    Your Software Vendor Is Not Your Partner. Protect Yourself Anyway.

    Your software vendor does not care whether your...
  • Backup and recovery icons for computer overlaid on people working on computers

    Why Your ‘Off-Site’ Backup Isn’t Really Off-Site (And Why That Matters)

    I need to tell you about a conversation I had l...
  • The Government Just Banned Most Home Routers. What Does That Mean?

    A client forwarded me a message from her intern...
  • The AI That Was Too Dangerous to Release Just Got Leaked

    I have been saying for a while now that the AI ...

Archives

  • GET SOCIAL
Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

© 2016 All rights reserved.

TOP