McAfee blog enabled IE exploit

An Israeli security researcher has published exploit code for an unpatched hole in Internet Explorer that Microsoft disclosed two days ago, using clues from a McAfee report on the hole.

Microsoft had warned in an advisory that a new vulnerability in IE6 and IE7, which could allow an attacker to take control of a computer, had been targeted in attacks.

Releasing the exploit code publicly increases the chances of attacks on the zero-day hole and could pressure Microsoft to issue a patch before its next scheduled Patch Tuesday in four weeks.

Researcher Moshe Ben Abu announced his work in a blog post on Wednesday and said it was being included in the open-source Metasploit exploit database.

He was able to create the exploit code after figuring out where an existing exploit was in the wild, based on information in a McAfee blog post, he told Ryan Naraine of the Zero Day blog at ZDNet.com.au sister site ZDNet.com. It took him about 10 minutes to de-obfuscate the exploit and pinpoint the vulnerability, he said.

Ben Abu said that he would have found the original exploit code sooner or later without McAfee's help.

Asked how serious the zero-day hole is, he wrote in an email: "The exploit covers Internet Explorer versions 6 and 7, which are not the latest version [IE8] but many users still use it. In addition, the exploit is quite unstable, with about 60 per cent to 70 per cent success rate. So I guess it is critical, but not for users who update their Windows with the latest IE."

Microsoft's advisory on the vulnerability includes information on workarounds but suggests that IE6 and IE7 users upgrade to IE8 immediately.

McAfee said it would be more careful about the details provided in its blog posts in the future.

"McAfee Labs does not support the release of exploit code, particularly in advance of a security patch being made available. We regularly sanitise blog content to prevent providing information that might assist attackers, while at the same time providing a service to customers and the security community to help improve protection levels," it said in a statement via email.

"The post in question did not contain enough information to directly lead anyone to exploit code. However, we regret that in this unique situation the post did contain details that may have given exploit writers a starting point to hunt for exploit code. Future blog posts will be subject to additional sanitisation."

Via CNET

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

NSW Govt appoints Silicon Valley champion - ZDNet Australia http://t.co/uCT03Ldu

Santos' thin client starts big-data plans #redhat
http://t.co/xydeKiCB

Android's biggest security flaws http://t.co/mCVUAZ6P via @zdnetaustralia

RT @teksquisite: Anonymous hacks Bureau of Justice, leaks 1.7GB of data http://t.co/OwfZ4csk

what a non-story. these thing happen all the time. is zdnet short on material?

18 minutes ago by paulwrussell on Spotify launch suffers redirect bungle

NSW Govt appoints Silicon Valley champion: The NSW Government has appointed an Australian champion for the techn... http://t.co/NRIajjiv

NSW Govt appoints Silicon Valley champion: The NSW Government has appointed an Australian champion for the techn... http://t.co/31SWsqJt

New #iPad case/stand could revolutionize #flying coach - @ZDNet (blog) : http://t.co/neUcgj4k

4 months old phone died. Took 6 weeks, three visits to the authorised repairer (Fonebiz) to "fix it". 2nd hand untested parts used, I say...

21 minutes ago by paracin on Sony Ericsson Xperia Arc S

Anonymous hacks Bureau of Justice, leaks 1.7GB of data http://t.co/OwfZ4csk

AusCERT 2012: contemplating the end http://t.co/oQFewLXr

Android's biggest security flaws| ZDNet Australia http://t.co/oVIpu1PE

Android's biggest security flaws| ZDNet Australia http://t.co/ApyNPcUF

It's easy to rubbish an old operating system long after the rest of the world has already passed judgement upon it. I would be far more i...

1 hour ago by ramnet on Microsoft admits Vista was 'cheesy'

Spotify launch suffers redirect bungle http://t.co/qUkSYPJB via @zdnetaustralia

Best user comment: "If Vista is cheesy, Metro is an over-ripe Stilton." http://t.co/ZJUwaxJT

If Vista is cheesy, Metro is an over-ripe Stilton.

1 hour ago by meski on Microsoft admits Vista was 'cheesy'

A farewell to democracy: Kaspersky - ZDNet Australia - A farewell to democracy: KasperskyZDNet AustraliaWithout inte... http://t.co/4Chwa6uL

A farewell to democracy: Kaspersky http://t.co/mOhiBgDu

Spotify launch suffers redirect bungle http://t.co/EZeHfNeb

RT @zdnetaustralia: What are Android's biggest security flaws? http://t.co/SJoTiDUY ^ST

Chief Marketing Officer - the hottest seat in the C-suite http://t.co/Gfnvwm7c

you are kidding right - what qualification do you have to make such wildy stupid statements - do you really have customers who pay you fo...

1 hour ago by rant rant rant on National Botnet Network coming: Earthwave

Spotify launch suffers redirect bungle - ZDNet Australia http://t.co/VmBsbPL8

Spotify launch suffers redirect bungle - ZDNet Australia http://t.co/E1kTrltd

Spotify launch suffers redirect bungle http://t.co/8UP4lyd1

by http://t.co/vmlQ0Ecb: Spotify launch suffers redirect bungle: Spotify's Australian launch seems to have failed... http://t.co/FRd6qAFw

Spotify launch suffers redirect bungle http://t.co/KPzJd2I8

Chrome overtakes IE: does it matter?: Google's Chrome appears to have become the most-used browser, having surpa... http://t.co/RJH13wPw

#Qantas promotes Strategy & Technology Head to #Jetstar CEO role from July 2012 http://t.co/bn5lmRRe

Monday madness Anonymous hacks Bureau of Justice http://t.co/GZ2jD9iO

A farewell to democracy: Kaspersky - ZDNet Australia http://t.co/I4NUagc8

A farewell to democracy: Kaspersky - ZDNet Australia http://t.co/50zNZ6O3

Spotify launch suffers redirect bungle: Spotify's Australian launch seems to have failed on at least one level: ... http://t.co/9btrXux2

Spotify launch suffers redirect bungle: Spotify's Australian launch seems to have failed on at least one level: ... http://t.co/9BvAawhj

A farewell to democracy: Kaspersky - ZDNet Australia http://t.co/qXfkgh8l #australia #technews

Spotify launch suffers redirect bungle: Spotify's Australian launch seems to have failed on at least one level: ... http://t.co/9BvEI6id

A little QA goes a long way. Spotify's redirection bungle http://t.co/NL5gCATG ^ST

Kaspersky says that democracy is threatened if we don't get a handle on e-voting http://t.co/w4Wgrqod ^ST

RT @lukehopewell: Eugene Kaspersky: without online passports, democracy will fall apart within 20 years http://t.co/nkNPUcph [COOL!]

Exactly. There are two topics of discussion, that are co-mingled; 1) Unauthorized software was put on the company device, by an IT person...

5 hours ago by lamont on ABC's Bitcoin miner tackled in minutes

Of course, it's true and it may be quite unnerving and mind-boggling, to begin thinking about selling or buying precious jewelry. This, o...

10 hours ago by Sanchezgavi5 on Don't add Telstra deal to NBN cost: Quigley

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

14 hours ago by rizowski on ABC's Bitcoin miner tackled in minutes

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

15 hours ago by Kevin Cobley on National Botnet Network coming: Earthwave

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

20 hours ago by anonymuos on Microsoft admits Vista was 'cheesy'

Gotta agree. For our Burnie, Tas. internet, we have a 1.5MB download speed adls connection through exetel using testra copper line. ADS...

21 hours ago by brozza on Broadband Speedtest

Well the message certainly is clear. Never do anything because something might happen. Seriously it seems to me "Earthwave" just want to...

23 hours ago by Hubert Cumberdale on National Botnet Network coming: Earthwave

you really think it's going to be such a grim future? looking at South Korea, Japan, even Czech Republic - I haven't seen either emit mo...

1 day ago by romant on National Botnet Network coming: Earthwave

No... they'll just blame the NBN for that too ;-)

1 day ago by Beta on National Botnet Network coming: Earthwave

It seems that some of the people who set up ACCAN (not staff members) took the view that it would somehow be against their view of 'consu...

1 day ago by socrates on ACCAN gets govt tick amid industry criticism

Don't laugh, Mr Turnbull is dumb enough to try and use this against the NBN. I'm sure the noallitions magical FTTN will be impervious to ...

1 day ago by Jingles on National Botnet Network coming: Earthwave

OMG, the sky will fall if we get NBN - it must be cancelled immediately! Sorry; was just channelling Malcolm Turnbull there for a moment...

1 day ago by socrates on National Botnet Network coming: Earthwave

Thats just stupid.. what else is the NBN going to get blamed for? People die crossing the road, are you going to ban cars or police it b...

1 day ago by fibretech on National Botnet Network coming: Earthwave

And again - missed this bit did you? "... Telstra is responsible for estates where development approval was granted before 1 January 201...

1 day ago by Beta on Copper greenfield dominance irrelevant: Conroy

I think the idea of dropping aero glass bit of a mistake. At least have some colour. Thats something i liked (especially after working on...

1 day ago by JCOZ on Microsoft admits Vista was 'cheesy'

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar