Monday, April 28, 2014

Give Me a Break

Bill Gates’ Microsoft Corp. announced on Saturday that Internet Explorer versions 6 through 11 are all vulnerable to a glitch that when properly exploited can give hackers remote access to a victim’s computer.

[...]

A person with knowledge of the vulnerability may create a fake website that, when visited, allows the hacker to exploit the bug and break into their target’s machine, Microsoft warned.

"An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change or delete data; or create new accounts with full user rights," the company advised.

According to FireEye spokesman Vitor De Souza, hackers had already taken advantage of the exploit by targeting unnamed US-based firms that are tied to the defense and financial sectors.

[...]

Microsoft was unable to patch the vulnerability by the time the weekend was over, and the United States government’s Computer Emergency Readiness Team (CERT) issued an alert warning computer users to “consider employing an alternative web browser.”

"We are currently unaware of a practical solution to this problem," Carnegie Mellon's Software Engineering Institute warned in an advisory of its own.

  RT
I bet they get that sucker patched PDQ, though.

No comments: