news4geeks.net
14Jun/120

Internet Explorer flaw triggers Gmail nation-state attack message

A security flaw in Internet Explorer is triggering messages in some users’ Gmail accounts that they may be the target of an attack from a nation-state.

The vulnerability in IE was revealed by Microsoft on "Patch Tuesday," a day designated by the company every month to move fixes to its software programs.

Although the package of fixes includes a patch to address the vulnerability in IE, the flaw triggering the warning message was not addressed in the package.

"The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer," Microsoft explained in an advisory.


In order for a hacker to exploit the vulnerability, an IE user needs to land on an infected webpage. To steer traffic to such pages, cybercriminals will typically use phishing e-mails or instant messages containing links to the infected locations.

Until Microsoft patches the vulnerability, the company is offering a temporary solution that can be downloaded from its Technet website.

According to cybersecurity software maker Trend Micro, the vulnerability has prompted Google to issue warnings to some of its Gmail users. "Google is flagging attempts to exploit this vulnerability by noting 'Warning: We believe state-sponsored attackers may be attempting to compromise your account or computer,'" it said in an e-mail to PCWorld.

"Reports show that this vulnerability has been used to compromise Gmail accounts," it added.

A number of Gmail users have reported on Twitter that they received the nation-state warning, but those tweets date back to days before the Microsoft advisory. Therefore, there's no way to know if they were triggered by the vulnerability or some other attack on Gmail users.

Google added the nation-state warning earlier this month. The warning doesn't mean that a Gmail account has been compromised, only that Google has detected that an account is under attack. Google declined to release details about how it knows one of its Gmail accounts is under attack.

The vulnerability in IE that allows the drive-by attacks is located in Microsoft XML Core Services. Microsoft XML Core Services provides a set of W3C compliant XML APIs that allows users to use Jscript, VBScript and Microsoft development tools to develop XML 1.0 standard applications, Trend Micro explained in a blog.

Using the vulnerability, it said, an attacker can craft a website to host a malicious webpage invoking affected MSXML APIs, which in turn accesses a COM object in memory that has not been initialized. The vulnerability is exploited when a user opens these crafted pages using IE.

(Source: infoworld.com)

 

Facebook: We’ll show you our PUE, now you show us yours
The data center industry has come a long way from the days when organizations closely guarded their efficiency secrets. Facebook is now the poster child for green-data center ...
READ MORE
Microsoft is in hot water with big-brand advertisers over its implementation of Do-Not-Track by default in the latest iteration of its Internet Explorer browser. The ad-slingers say Internet ...
READ MORE
Microsoft has promised it will release a fix “in the next few days” to address the recently-identified flaw in Internet Explorer. At the time of writing, it is only possible ...
READ MORE
Researchers from security vendor AlienVault have identified a variant of a recently discovered Internet Explorer exploit that is used to infect targeted computers with the PlugX RAT (remote access Trojan) program. The ...
READ MORE
Despite years of pressure from government antitrust actions and open-source upstarts like Mozilla Firefox and Google Chrome, Microsoft's Internet Explorer (IE) browser still commands more than 50 per ...
READ MORE
Facebook: We’ll show you our PUE, now you
Top admen beg Microsoft to switch off ‘Do
Microsoft promises two-step IE fix
New IE exploit variant used to distribute PlugX
Internet Explorer needs fresh dev infusion for a

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.