Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • 5 Active Malware Campaigns in Early 2025: What You Need to Know
    • 10 Critical Network Pentest Findings IT Teams Overlook
    • Report Phishing Instantly with PhishAlarm
    • Password Reuse Epidemic: Nearly Half of User Logins Compromised
    • Women in Cybersecurity: Interest, Exposure, or Just Stereotypes??
    • Stay Ahead of Scammers in 2025
    • Cybersecurity Alert: Risks of Abandoned Websites
    • DHS Unveils Playbook for the Deployment of Artificial Intelligence for the Public Sector
    Fordham University Information Security and Assurance
    • Information Security and Assurance Homepage
    • Privacy Blog
    • About
    Fordham University Information Security and Assurance
    You are at:Home»Alerts»**** Internet Explorer 0-Day Vulnerability ****
    Alerts

    **** Internet Explorer 0-Day Vulnerability ****

    By Shannon OrtizJanuary 20, 2010Updated:February 6, 20192 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Copy Link

    You may or may not already know that an unpatched vulnerability for Internet Explorer was announced last week. On Friday, exploit code was made public so it’s likely that we’ll start seeing exploitation on campus soon. Here are the details:

    === VULNERABILITY INFO ===
    The vulnerability can be exploited when a client visits a malicious webpage (clicking a link in an email, visiting a website that contains a malicious advertisement, or visiting a website that has been compromised itself and is unknowingly hosting malicious content). Exploit code has been publicly released, and although we have not yet received reports of widespread exploitation I would expect that’s likely to change soon.
    Current exploits function only against IE6. Although the vulnerability is present in IE7 and IE8 as well, the current public exploit code fails on those platforms.
    === Workarounds ===
    Microsoft is likely to release a patch soon, outside of their normal patch-Tuesday cycle. Keep an eye out for it.
    If you have users who are still using IE6, now would be a great time to get them upgraded. Current exploit code doesn’t work against IE7 or IE8, and although the vulnerability is present in those browsers it’s likely that MS will have a patch out before attackers can adapt the exploit code to work on them.
    As an alternative to upgrading, you could also set the “security level” for the “Internet Zone” to high for IE6 in Tools — Internet Options — Security Tab — Internet Zone — set security-level slider to “high”. This disables JavaScript among other things which may degrade performance for some sites. Sites that are needed for business purposes and rely on the disabled features should be added to the “trusted sites” list in the same preference tab listed above, for example add *.nyu.edu there.
    A more narrowly scoped workaround is to manually disable JavaScript for IE6 in Tools — Internet Options — Security Tab — Internet Zone — Custom Level — Scroll down to “Active Scripting” and disable. Sites that are needed for business purposes and rely on JavaScript should be added to the “trusted sites” list in the same preference tab listed above, for example add *.nyu.edu there.
    === LINKS ===
    MS Advisory with details on the vulnerability:
    http://www.microsoft.com/technet/security/advisory/979352.mspx
    MS security blog posts with more technical details:
    http://blogs.technet.com/srd/archive/2010/01/18/additional-information-about-dep-and-the-internet-explorer-0day-vulnerability.aspx
    http://blogs.technet.com/srd/archive/2010/01/15/assessing-risk-of-ie-0day-vulnerability.aspx

    Share this:

    • Click to share on X (Opens in new window) X
    • Click to share on Facebook (Opens in new window) Facebook
    • Click to share on LinkedIn (Opens in new window) LinkedIn

    Like this:

    Like Loading...
    Alerts Exploits and Vulnerabilities
    Previous ArticleWEBMAIL HELPDESK- Phishing Email Sent to Fordham Community on 10/02/2009
    Next Article IRS Annual Notification- Phishing Email Sent to Fordham Community on 11/18/2009

    Related Posts

    Password Reuse Epidemic: Nearly Half of User Logins Compromised

    Cybersecurity Alert: Risks of Abandoned Websites

    Incident Response: Why Everyone Needs a Plan for Cyber Threats

    Follow Us on Twitter!
    Follow @FordhamSecureIT
    My Tweets
    Archives
    Categories
    • AI (1)
    • Alerts (384)
    • CISO (19)
    • Cyber Security Awareness Month Tip (150)
    • Data Privacy Week (2)
    • Executive Director (1)
    • Exploits and Vulnerabilities (35)
    • General Information (34)
    • Identity and Access Management (12)
    • Identity Theft (26)
    • Jason Benedict (19)
    • Legitimate Email (14)
    • Malicious Email (24)
    • Mobile (25)
    • Network Security (2)
    • News and Events (143)
    • Newsletter (13)
    • Password (17)
    • Phishing (333)
    • Phishing Email (340)
    • Privacy (10)
    • Ransomware (9)
    • Scam (104)
    • Security Awareness (262)
    • Security Guides (34)
    • Social Engineering (12)
    • SPAM (40)
    • Suspicious (6)
    • Telework (2)
    • Teleworking (3)
    • Trojan (7)
    • Uncategorized (9)
    • Virtual Meeting (4)
    • Virus (28)
    • Viruses (8)
    • World Backup Day (1)
    • Zoom (6)
    Tag Cloud
    Alerts Artificial Intelligence Backups cell phones CISO Cybersecurity Awareness Month Tip Cybersecurity Month Data Privacy Device email Exploits and Vulnerabilities fordham fraud Identity and Access Management Identity Theft Information Security Guides Jason Benedict Legitimate Email malicious email Mobile Multi-Factor Authentication networks Network Security News and Events Newsletter online safety Online Shopping Password Phishing Phishing Email Privacy ransomware scam scams Security Awareness social engineering Social Media spam trojan Virus Viruses Wireless wire transfer scam World Backup Day zoom
    About
    About

    Founded in 1841, Fordham is the Jesuit University of New York, offering exceptional education distinguished by the Jesuit tradition to more than 15,100 students in its four undergraduate colleges and its six graduate and professional schools.

    Copyright © Fordham University
    Facebook X (Twitter) Instagram YouTube LinkedIn
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    %d