Microsoft Short On Change
Exploit code for this flaw exists in the wild in the form of malicious JavaScript on (mostly) chinese malware-spreading websites. The flaw was published by Chinese IT security outfit Knownsec.
http://www.scanw.com/blog/archives/303
Non-chinese-reading readers are advised to use the google-translated version we've provided a link to here.
The exploit is used to download and execute a known Trojan, so most AV users are relatively safe for the moment. However, the minute the payload is changed, the picture will become completely different. Remains to be seen if Microsoft will issue an out-of-cycle patch or wait for the usual month before acknowledging and fixing the issue.
Article rating:
- |
- Send on Yahoo!
- |
- RSS

Copyright 2010. Site powered by BitDefender