(1888PressRelease)
December 12, 2008 - “Internet Explorer remote code execution vulnerabilities have very high impacts since the source of the malicious payload can be across any site on the Internet,” said Andre Protas, eEye’s Director of Research and Preview Services. “An even more critical problem is generated when clients are administrators on their local hosts, which would run the malicious payload with Administrator credentials.”
Disclosed on 12/9/08, the common name for this critical severity-level exploit is known as the Microsoft Internet Explorer 7 XML Zero-Day. The patch release date is still unknown from Microsoft, but it has a high likelihood of an out-of-band patch, an uncommon but important part of Microsoft’s patching process.
Affected applications include:
IE7 on Windows XP
IE7 on Windows Server 2003
IE7 on Windows Vista (Not Currently Targeted)
Said Protas, “The good news is that eEye’s Blink Client Security protected systems from this vulnerability without the need for an update. Pure zero-day protection -- this is what matters most to administrators. eEye Retina was updated with an audit to help detect systems that have Internet Explorer 7 set as the default browser.”
In addition, eEye’s Preview Services delivered advanced security intelligence on the IE7 vulnerability to its customers including fully-functional exploits for testing; a twelve-page document about the vulnerability, and full details on the attackers that identified and helped distribute the vulnerability details.
For information regarding the potential risks and remediation requirements of Microsoft Patch Tuesday’s and related announcements, eEye offers a monthly Vulnerability Expert Forum webinar the Wednesday following Patch Tuesday which provides valuable insight regarding new vulnerabilities that are discovered and the actions that need to be taken as a result. (Patch Tuesdays are released the second Tuesday of the month)
About eEye Digital Security
eEye Digital Security is a leader in vulnerability management, endpoint security, anti-virus software and IT security research. The company’s advanced security solutions help technology professionals protect the networks and digital assets of more than 9,000 corporate and government organizations worldwide. Founded in 1998, eEye Digital Security is headquartered in Orange County, California. For more information, please visit www.eEye.com.
Press Contacts
Agency: Victor Cruz, MediaPR, 1.508.655.4397 | email: eEye ( @ ) mediapr dot net
Corporate, North America: Stacy Newman, 1.949.333.1913 | email: press ( @ ) eEye dot com
###