Microsoft Rushes Fix for IE Hole Used in Attacks on DC’s Elite
ID: 59c8457f-ac1d-5f3f-b1d4-d00521f2c546
STIX ID: report--59c8457f-ac1d-5f3f-b1d4-d00521f2c546
Feed Name: Security Ledger
Microsoft issued an emergency fix for a zero-day remote code execution vulnerability in Internet Explorer 6–8 after security researchers discovered a targeted watering-hole campaign that used a Flash-based heap-spray and a “drive by cache” technique on the Council on Foreign Relations website to deliver information-stealing malware to selected visitors (notably IE8 users and systems configured for certain language locales). FireEye and others analyzed the activity (dating from ~Dec 21), Microsoft published a temporary 'MSHTML Shim Workaround' and recommended upgrades to non-vulnerable IE versions or use of EMET to mitigate the exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
