NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Internet Explorer

Internet Explorer


Internet Explorer 8 Critical Zero-Day Security Vulnerability Released in the Wild

"Courtesy" of Aviv Raff

By Marius Oiaga, Technology News Editor

9th of May 2008, 13:36 GMT

Adjust text size:


Internet Explorer
Enlarge picture
It is just a little over two months since the first public testing milestone for Internet Explorer was made available outside of Redmond, and a
critical 0-day security vulnerability impacting the browser has already been released in the wild. Security researcher Aviv Raff has tucked away an exploit somewhere on his blog and issued an invitation for visitors for a little game of vulnerability treasure hunt. According to Raff, both Internet Explorer 7 and Internet Explorer 8 Beta 1 are susceptible to attacks. The researcher stated that he was releasing the vulnerability as part of the celebration of Israel's 60 years of independence.

"As part of the celebration, I'm releasing a new 0day vulnerability. (...) In the spirit of this day, I've decided not to release full details about this vulnerability yet, but rather play a little 'treasure hunt' game. Somewhere in my blog, I embedded a proof-of-concept code which exploits this 0day vulnerability," Raff stated.

Microsoft failed to issue an official comment on the IE7 and IE8 Beta 1 vulnerability game, but it seems that so far, none of the visitors to the security researcher's website managed to come across the exploit code. This even if they were supplied with a number of clues to help them identify the attack, including: "IE7.0 and IE8.0b users will get pwned. An interaction with the sploit is needed. There's no need to find the post. It's everywhere. 404 is the way to go. Acidus was right! 'Local resources' is the key."

However, Raff is willing to take it a step further. On may 14, 2008, he plans to make public all the details related to the vulnerability. "Next Wednesday I will release the full technical details of this 0day vulnerability and the proof-of-concept code," Raff promised. Of course that the published proof-of-concept will enable all potential attackers to build exploits using the zero day vulnerability and target Internet Explorer 7 and Internet Explorer 8 Beta 1 users.

TAGS:

IE7 | IE8 | Beta 1 | 0-day | vulnerability
Read by 2,837 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.3/5) 9 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Internet Explorer 8 Beta 1 ActiveX Security

Original XP SP3 RTM Integrated Slipstream ISO Images Leaked

XP SP3 Ships Complete with a Range of Issues that Survived RTM

Mozilla Nearing the Finish Line for Firefox 3.0

IE8 Beta 1 Fixing What's Wrong with IE7

Microsoft Launches IE 8 Beta 1 and IE7 Tree-Hugging Exclusive Website

IE8 Beta 2 Will Fix What's Wrong with Beta 1

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM