Slashdot Mirror


New IE 8 Zero Day Discovered

Trailrunner7 (1100399) writes "Researchers have disclosed a new zero day vulnerability in Internet Explorer 8 that could enable an attacker to run arbitrary code on vulnerable machines via drive-by downloads or malicious attachments in email messages. The vulnerability was discovered and disclosed to Microsoft in October, but the company has yet to produce a patch, so HP's Zero Day Initiative, which is handling the bug, published its advisory Wednesday. The ZDI has a policy of disclosing vulnerability details after 180 days if the vendor hasn't produced a patch. The use-after-free flaw lies in the way that IE handles CMarkup objects, and ZDI's advisory says that an attacker can take advantage of it to run arbitrary code."

6 of 134 comments (clear)

  1. Enough already by Anonymous Coward · · Score: 2, Funny

    I've had it. Nothing is secure. Nothing works. I'm going back to an abacus and an Etch-a-Sketch.

  2. October?! by anarkhos · · Score: 2, Funny

    Can't Balmer spare any developers developers developers?

    --
    >80 column hard wrapped e-mail is not a sign of intelligent
    >life
  3. Re:why are they taking so long? by Billly+Gates · · Score: 2, Funny

    that's was a rethorical question, btw. I suppose incompetence of an almost petrified juggernaut. or maybe fixing it would break some obscure feature someone pays for.

    No way. You mean something written only for IE with professional quality like Taleo, workday, McKearson, and PeopleSoft would break when turning on sandboxing, tls 2.0, non compromised certicates, local admin activeX controls, when turning on security and w3c standards? Oh please. If that were the case I am sure the cost accountants would be approving upgrades to use the latest versions.

  4. It is not a zero day. by 140Mandak262Jamuna · · Score: 5, Funny

    According to the timeline it is a -180 day.

    --
    sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
  5. Re:Don't blink this time MS by Anonymous Coward · · Score: 2, Funny

    Fuck you! XP FOREVER!!!!!

  6. Re:why are they taking so long? by lennier1 · · Score: 3, Funny

    The NSA probably wanted more time to exploit it.