Yet Another IE6 & 7 Vulnerability

This comes after the recent Chinese Aurora attacks, the vulnerability is based around incorect pointer dereferencing (use after free) in iepeers.dll. Enabling Data Execution Prevention (DEP) on Windows Vista/7 will prevent successful exploitation, however XP has no defence.

Switch to IE8 or Firefox right now if you haven’t done so already!

Microsoft Advisory: http://www.microsoft.com/technet/security/advisory/981374.mspx

New Metasploit module: http://www.metasploit.com/modules/exploit/windows/browser/ie_iepeers_pointer

Original 0-Day: http://www.rec-sec.com/2010/03/10/internet-explorer-iepeers-use-after-free-exploit/

Leave a Reply

You must be logged in to post a comment.