logo

Microsoft Rushes Fix for IE Hole Used in Attacks on DC’s Elite

ID: 59c8457f-ac1d-5f3f-b1d4-d00521f2c546

STIX ID: report--59c8457f-ac1d-5f3f-b1d4-d00521f2c546

Feed Name: Security Ledger

Threat Score
78/100

Date Published: 2013-01-02

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Microsoft issued an emergency fix for a zero-day remote code execution vulnerability in Internet Explorer 6–8 after security researchers discovered a targeted watering-hole campaign that used a Flash-based heap-spray and a “drive by cache” technique on the Council on Foreign Relations website to deliver information-stealing malware to selected visitors (notably IE8 users and systems configured for certain language locales). FireEye and others analyzed the activity (dating from ~Dec 21), Microsoft published a temporary 'MSHTML Shim Workaround' and recommended upgrades to non-vulnerable IE versions or use of EMET to mitigate the exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.