Look out, Internet Explorer users. eWeek reports that Microsoft will release a patch for a zero-day IE vulnerability later today. Apparently, the vulnerability has to do with IE's data binding function, and malicious hackers have already managed to exploit it. Here's the skinny in Microsoft's words:
The vulnerability exists as an invalid pointer reference in the data binding function of Internet Explorer. When data binding is enabled (which is the default state), it is possible under certain conditions for an object to be released without updating the array length, leaving the potential to access the deleted object's memory space. This can cause Internet Explorer to exit unexpectedly, in a state that is exploitable.
eWeek quotes Microsoft's Christopher Budd as saying, "At this time, we are aware only of attacks that attempt to use this vulnerability against Windows Internet Explorer 7." That sounds like one of the few occurrences when running IE6 might actually be a good thing, although you're probably still better off running a non-Microsoft browser like Firefox, Safari, Chrome, or Opera.
Until the fix comes out, Microsoft cautions to watch out for instant-message file transfers and e-mail attachments. Since exploiting the hole can give a hacker the same rights as the user, not running with administrative privileges (as in Vista with UAC enabled) might help, too.
Update: The patch is now out. You can download it from this page on Microsoft's website.
|1. Hdfisise - $600||2. Ryszard - $503||3. Andrew Lauritzen - $502|
|4. the - $306||5. SomeOtherGeek - $300||6. Ryu Connor - $250|
|7. doubtful500 - $200||8. Anonymous Gerbil - $150||9. webkido13 - $135|
|10. cygnus1 - $126|
|Logitech's MX Master and MX Anywhere 2 mice reviewed||28|
|Reports: Win10 gaming performance similar to Win8.1||50|
|The International Dota 2 Championships puts $18 million up for grabs||5|
|EVE: Gunjack brings on-rails space shooting to Gear VR||2|
|Spoofed Win10 update emails carry nasty ransomware||9|
|AMD's Exascale Heterogenous Processor is the server APU||45|
|Nokia sells Here maps to auto consortium for $3.06 billion||11|
|The TR Podcast 182: Something happened||21|
|Stingray 3D engine burrows into Autodesk products||3|