You are here: silicon.com > Software > Malware

Malware

Warning: IE 7 at risk from malicious exploit

Potential for 'widespread' infection

Tags: browser, microsoft, ie7, exploit

By Dawn Kawamoto

Published: 17 December 2008 08:55 GMT

Microsoft issued a critical security warning Tuesday that a malicious exploit is making the rounds and attacking vulnerabilities in Internet Explorer 7.

The risk is believed to be widespread, given that IE 7 is the latest version of Microsoft's browser and is bundled with XP service pack 3 and also Vista, said Dave Marcus, director of security research and communications for McAfee's Avert Labs.

The AZN Trojan, which has been making the rounds since the first week of December, has the potential of infecting users' systems with a Trojan horse, or "downloaders" that can download other forms of malware onto a user's system.

Microsoft announced it will release a security patch Wednesday via its automatic update system to patch users' computers.

Users can potentially get infected two ways, Marcus said. One is to visit a malicious website that already has the malware installed on the site, or visit a legitimate site, in which the attacker has inserted the malicious script to run in the background, leaving visitors unaware their systems have been compromised.

Marcus said: "A lot of websites are pushing out this exploit." Some of the infected sites include websites that offer free wallpaper for mobile phones to sites that feature property to product-related sites.

Microsoft is encouraging users to update their systems with the patch.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Information Security Analyst (Attack Monitoring/Data Leakage/CISSP/CEH)

In depth experience of working with Intrusion Detection (IDS), Threat Analysis and Malware & Trojan Research technologies and techniques are expected ...

OpenGL ES Graphics Driver Design Engineer

Primary responsibilities will include: Design and develop OpenGL ES graphics drivers to the Khronos specification to drive our current and next ...

Regional Manager Security Research Lead Malware Italy Spain or Sweden

Negotiable packageHome based office(should be within (sporadically) commutable distance of territory capitals)Our Client, an established global ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: