Dec 25, 2010

Internet Explorer zero day attack, just in time for Christmas

SlashDot - "Microsoft has released a notice about a neHTML clipboardhttp://raincoaster.files.wordpress.com/2007/12/deadsanta.jpg?w=535 zero day attack against Internet Explorer. Guess it's going to be less of a 'White Christmas.' 'Ok, fess up — who asked for an IE 0 day for Christmas? I'm guessing Santa got his lumps of coal mixed up with a bag of exploits. This exploit has been discussed over the last day or so on full disclosure and a number of other sites. Metasploit already has a module available for it (just search for CSS & IE). Microsoft has put out an advisory 2488013 regarding the issue which manifests itself when a specially crafted web page is used and could result in remote code execution on the client.'"