logo

Aurora Exploit Still Floating ...

ID: 21adf992-3adf-5509-8940-6d0a0c709aac

STIX ID: report--21adf992-3adf-5509-8940-6d0a0c709aac

Feed Name: Zscaler Security Research Blog

Threat Score
50/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report details a live Internet Explorer exploit of CVE-2010-0249 (Aurora) delivered via obfuscated JavaScript on compromised web pages: the payload corrupts memory through DOM manipulation and uses heap spray to run shellcode which downloads a malicious PE from listed URLs. The analysis includes deobfuscated code, extraction of the embedded executable, multiple observed malicious URLs (IoCs), and remediation advice to patch or upgrade browsers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.