New IE Information Disclosure Advisory…
Microsoft has announced in Advisory (980088) that there has been a publicly disclosed vulnerability in Internet Explorer, versions 5 through 8. Users not running Internet Explorer in Protected Mode are at risk of having information, in files with predictable names, accessed by attackers. This vulnerability cannot be exploited to execute remote code or used for a denial-of-service attack.
The largest group of users at risk are Windows XP users running IE without Protected Mode enabled. Internet Explorer on Vista and Windows 7 has Protected Mode enabled by default.
Though no patch exists at this time, users can protect themselves by simply enabling Protected Mode in Internet Explorer ( which may require upgrading to a version of IE that has Protected Mode ).
You can find more information on Microsoft Advisories and Bulletins at the SophosLabs vulnerability analysis page.
Source: http://www.sophos.com/blogs/sophoslabs/?p=8538
February 4th, 2010
Related posts
- Microsoft Explores Another IE Flaw After the Google Attack
- Security Advisory, Adobe Reader
- New Zero-Day exploit for Microsoft PowerPoint: Exploit/PPT
- 0-Day Exploit for all Windows Systems CVE-2010-0232
- Defence Lab (DefenceLab) Removal Instructions
- March Patch Tuesday …. pay attention Mac users
- Microsoft Vulnerabilities
- Black Tuesday – and December so far…
- EXPL_NEVAR: Another Post-Disclosure Exploit
- Exploit Shield FTW
