Blog

New Internet Explorer Zero-Day being utilized.

09.19.2006 - 8:45 AM
As of last night a new Internet Explorer "zero-day" exploit is being utilized on the Internet. The exploit appears to use a weakness within VML inside Internet Explorer (details: http://sunbeltblog.blogspot.com/2006/09/seen-in-wild-zero-day-exploit-being.html).

We will be reporting details later this morning with a full alert, however its important to note that the sites that have been identified to date were classified previously by us as malicious because they were using the Web Attacker Toolkit (more details http://www.websense.com/securitylabs/alerts/alert.php?AlertID=520).

Although we do not have evidence that the web attacker toolkit has been updated, there is a high level of probability that is has as they have been on top of exploits in the past. Currently there are thousands of sites on the web that use the Web Attacker Toolkit which may lead to high numbers of sites exploiting this newest unpatched vulnerability.

Bookmark This Post:

Post a Comment: