Internet Explorer vulnerable on Windows 7

happygeek 1 Tallied Votes 1K Views Share

So it seems that an Internet Explorer zero day vulnerability allowed the back door to be opened that resulted in the hack attack on Google and many others that has received such publicity this week.

According to McAfee it has identified an Internet Explorer vulnerability as being one of the attack vectors but the security vendor also warns that targeted attacks such as this often use "a cocktail of zero-day vulnerabilities combined with sophisticated social engineering scenarios" so it is possible, likely even, that other as yet unidentified attack vectors were also involved. However, McAfee dismisses some early reports which claimed that an Adobe Reader PDF vulnerability was a factor, stating that there is simply no evidence to suggest this to be the case.

Worryingly though, McAfee does insist that while "this attack is especially deadly on older systems that are running XP and Internet Explorer 6" and this was the focus of these recent attacks, Internet Explorer does remain "vulnerable on all of Microsoft’s most recent operating system releases, including Windows 7". McAfee says that new versions of Windows simply make exploiting the vulnerability harder, not impossible.

It becomes even more worrying when you appreciate that the code used in the Google attack to exploit the as yet unpatched vulnerability has now been published on the web for anyone to grab and make use of. Unlike some other news publications, DaniWeb will not be making things easier yet by linking to the website concerned.

Dani AI

Generated

Good historical summary and sensible reactions from the thread. For clarity and a concise follow‑up:

The exploit used in the 2009/2010 "Operation Aurora" attacks was tracked as the HTML Object memory‑corruption issue CVE‑2010‑0249 and was fixed by Microsoft in the January 2010 cumulative Internet Explorer update (MS10‑002). The bugs made successful, targeted attacks practical against IE6, and proof‑of‑concept/exploit material later appeared in the wild; Microsoft published guidance and then issued the security bulletin and update. MS10‑002CVE‑2010‑0249 summary.

Practical takeaways that remain valid years later: 1) If the machine is still in use, install all relevant security updates (the Jan 2010 IE cumulative update and every later patch for your platform) or confirm they are installed via Windows Update/Update history. 2) Browser choice matters: switching to a browser that receives frequent security updates reduces exposure (as and suggested), but any browser must be kept current. 3) OS mitigations (Protected Mode, DEP/ASLR) in Vista/Windows 7 made exploitation harder but did not guarantee immunity — they were mitigation layers, not fixes. Microsoft MSRC advisory

Final note for anyone reading this years later: legacy platforms matter. Windows 7 reached end of support on January 14, 2020; running an out‑of‑support OS greatly increases risk. Move to a supported OS or isolate the legacy host and keep browsers and protections current. Windows 7 end‑of‑support FAQ

happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

A 'Microsoft Spokesperson' has just contacted me to say this in response to the Internet Explorer vulnerability news:

Microsoft is aware of public exploit code released that impacts customers using Internet Explorer 6 and of limited, targeted attacks attempting to use this vulnerability against Internet Explorer (IE) 6. As a result of the reports, we released an to alert customers and provide actionable guidance and tools to help with protections against exploit of this IE vulnerability:

Customers using Internet Explorer 8 are not affected by currently known attacks and exploits due to the improved security protections in IE8. To help protect our customers, we recommend that all customers immediately upgrade to Internet Explorer 8. Customers should also consider applying the workarounds and mitigations provided in our Security Advisory such as putting Internet zone security settings to High.

Microsoft teams are continuing to work around the clock on an update and we will take appropriate action to protect customers when the update has met the quality bar for broad distribution. That may include releasing an out-of-cycle security update.

pitlin 0 Newbie Poster

For this I`d prefer firexof and chrome.

The Dude 944 Nearly a Senior Poster

All these things about IE6 all of a sudden seem a little bit suspicious to me,LIKE THEY ARE TRYING TO SCARE PEOPLE OFF OF IE6 AND GET THEM TO SOMETHING WHERE THEY HAVE MORE CONTROL!

Tcll 66 Posting Whiz in Training Featured Poster

while I do rate IE8 as the best IE for security (that I've used), I do agree with the MS-control.

I'm sure everyone remembers how much I've bamfed chrome, now I'm actually using it and rate it above Comodo IceDragon after having switched to linux. :P
http://tcll5850.proboards.com/thread/268/sincere-apology-google

though, there are rumors about google spying on everything...
I do believe this was removed in Dragon.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.