dimanche 6 octobre 2013

Exploits, more details for unpatched IE vulnerability

Summary: Three separate campaigns directed attack have been using the vulnerability, and now has gone an exploit in Metasploit. Microsoft has released a solution, but not a patch.

The SANS Internet Storm Center reports that Metasploit has released a module exploit for an unpatched Internet Explorer vulnerability disclosed by Microsoft last week.

Exploitation module must grease the wheels so the attackers try to infect the systems of the users, but according to security company FireEye, who first revealed the attacks using the vulnerability, 3 separate campaigns being conducted using already.

Microsoft has published a correction of the vulnerability, which has been designated CVE-2013-3893, but still has no word on when it will be available for him or if Iran out of band to do a patch. Microsoft has also published instructions on the advice on how to use your EMET tool to block attacks.

Larry Seltzer has been a recognized expert in technology, with emphasis on mobile technology and security in recent years

Aucun commentaire:

Enregistrer un commentaire