U.S. Homeland Security recommends not using IE until Microsoft releases patch

  • 29 April 2014
  • 0 replies
  • 106 views

Userlevel 7
Badge +52
This past weekend, Microsoft issued a security advisory for all supported versions of its Internet Explorer web browser, due to recently discovered attacks that used a newly found zero day exploit. The issue is so serious, the U.S. Homeland Security department has issued its own warning about the IE exploit.
 
The department's Computer Emergency Readiness Team has posted word on its website that Internet users and IT administrators should "enable Microsoft EMET where possible and consider employing an alternative web browser until an official update is available." It's rare that the team issues a security alert that offers a recommendation to stop using a specific web browser family,
 
Microsoft's original security advisory, released on Saturday, describes the nature of the exploit:
"The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer."

Full Article
 

0 replies

Be the first to reply!

Reply