UNSOLVED

ky331

updated

13 years ago

K

ky331

5 Journeyman

15622 Posts

45048 Points

0

10470

September 17th, 2013 19:00

IE 0-day vulnerability and Microsoft Fix-It

Microsoft has published an emergency advisory and Fix-it for users of its Internet Explorer.

Advanced users can use Microsoft EMET to mitigate exploitation of this flaw as recommended in Microsoft's advisory 2887505.

For everyday Windows users, Microsoft is also providing a temporary "Fix it" #51001 that changes your settings to provide protection until a permanent fix is available, but this only works in 32-bit versions of Internet Explorer.  (It is advisable that you also download the UN-do Fix-it #51002 now, as you may need to use this when Microsoft provides a "permanent" fix.)

References:  http://nakedsecurity.sophos.com/2013/09/18/internet-explorer-zero-day-exploit-prompts-microsoft-to-publish-emergency-fix-it/ 

https://technet.microsoft.com/en-us/security/advisory/2887505 

http://support.microsoft.com/kb/2887505

  • ky331

    5 Journeyman

    15622 Posts

    45048 Points

    89

    0

    Posted September 18th, 2013 16:00

    MalwareBytes is reporting that its Anti-Exploit program (MBAE) [which is in BETA] successfully blocks this particular vulnerability in IE:  "We’re pleased to report that Malwarebytes Anti-Exploit users were already protected from this vulnerability prior to its public release, as the vulnerability uses a special technique to execute malicious code that’s already blocked by Malwarebytes Anti-Exploit".

    http://blog.malwarebytes.org/whats-in-the-news/2013/09/microsoft-releases-fix-for-ie-zero-day/