Porn sites exploit new IE flaw

By Joris Evers on 21 September 2006

Tags: flaw | ie | patch | porn | security | windows | exploit | vulnerable | site | attack

Miscreants are using an unpatched security bug in Internet Explorer to install malicious software from rigged Web sites, experts warned Tuesday.

The vulnerability lies in the way IE 6 handles certain graphics. Malicious software can be loaded, unbeknownst to the user, onto a vulnerable Windows PC when the user clicks on a malicious link on a Web site or an e-mail message, several security companies said.

"Fully patched Internet Explorer browsers are vulnerable," Ken Dunham, director of the rapid response team at VeriSign's iDefense, said in an e-mailed statement. "This new zero-day attack is trivial to reproduce and has great potential for widespread Web-based attacks in the near future."

Security-monitoring companies Secunia and the French Security Incident Response Team have given the issue their most serious ratings.

Shady adult Web sites are among the first to exploit the IE vulnerability, Eric Sites, vice president of research and development at spyware specialist Sunbelt Software, wrote on a corporate blog. In one case, a malicious Web site used the exploit to install "epic loads of adware," according to Sunbelt.

Microsoft plans to fix the flaw as part of its monthly patching cycle on October 10, the software giant said in a security advisory. The update might be released sooner, "depending on customer needs," Microsoft said. Typically, Microsoft only breaks its patch cycle when attacks are widespread.

The number of attacks may rise quickly, according to Web security company Websense. It appears that WebAttacker, a tool often used to create attack sites, has been fitted with the new exploit, Websense said in an e-mailed statement. "We have confirmed multiple, previously known, WebAttacker sites that are currently exploiting this vulnerability to install malicious software," Websense said. "We expect to see many of the several thousand WebAttacker sites begin to utilise the exploit, as they update to the latest release of the tool kit."

"Microsoft is aware that this vulnerability is being actively exploited," the company said in its advisory. While it works on an update, Microsoft recommends users keep their security software updated and take caution when browsing the Web. In its advisory, it also provides several workarounds to protect systems against the flaw.

The vulnerability lies in a Windows component called "vgx.dll." This component is meant to support Vector Markup Language documents in the operating system. VML is used for high-quality vector graphics on the Web.

This is the second known and unpatched flaw for IE to surface in as many weeks. Last week Microsoft confirmed a flaw in an ActiveX control related to multimedia. Attack code that exploits the flaw and could be used to hijack Windows PCs running IE 5 or IE 6 has been posted on the Net. Microsoft also has yet to provide a patch for a Word 2000 flaw being exploited in targeted cyberattacks.

Like this article? Click below to send it to your mobile for free!

reddy
21/08/2007 01:24 AM

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • ZoneAlarm Internet Security Suite 2009

  • PC Tools to be poor man's Norton

  • Symantec wants another chance

  • Olympics cybersecurity

  • New worm targets Facebook, MySpace

  • The Mac uninstallers

  • First iPhone antivirus app released

  • Free Speed: Make your Mac faster

  • Apple fixes security issues with QuickTime 7.5

More articles »

Find the right software

Brand
  • Multiple options can be selected

    The Explain Series

    • ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security 2009 provides top-notch security protection that is light on system resources, allowing you to work unencumbered.

    • Ad-Aware 2008

      Ad-Aware 2008

      This year's update to user favourite Ad-Aware is quite a significant overhaul, and the result is faster scan times and a new interface.

    • AVG Internet Security 8.0

      AVG Internet Security 8.0

      AVG Internet Security 8.0 provides strong protection against malicious Web sites, but its full-system scans sometimes tax system resources and produce false positives.

    • Sunbelt CounterSpy 2.0

      Sunbelt CounterSpy 2.0

      In its first appearance, CounterSpy was the only antispyware product that correctly identified every piece of spyware in our current active-detection test.

    • Ad-Aware 2007

      Ad-Aware 2007

      Lavasoft Ad-Aware 2007 came in dead last in our CNET antispyware testing. Ad-Aware failed to detect half of the test spyware, and unlike nine out of the 10 other antispyware apps we reviewed in December 2007, left behind traces for all but one spyware.

    More reviews »

    Membership benefits

    Win prizes and other promotion benefits

    Win prizes and other promotion benefits

    As a CNET.com.au member, you're eligible to enter and win any prizes on our site. Sign up for a free CNET.com.au membership now!