Date Disclosed:
9/17/2013
Date Patched:
Patch Not Yet Available
Vendor:
Microsoft
Affected Software:
Internet Explorer 6
Internet Explorer 7
Internet Explorer 8 (in the wild, targeted attacks focusing on XP and 7)
Internet Explorer 9 (in the wild, targeted attacks focusing on XP and 7)
Internet Explorer 10
Internet Explorer 11
Description:
Severity:
High
Code Execution:
Yes.
Impact:
Remote Code Execution
Exploitation of this vulnerability is possible through the use of methods like drive-by attacks. Remote attackers who successfully exploit this vulnerability will be able to execute code on the vulnerable system with the same rights as the currently logged on user.
Mitigation:
Apply the Microsoft Fix it immediately to prevent exploitation. Additionally, EMET 4.0 mitigates this attack. Otherwise, use other browsers such as Chrome.
Protection:
BeyondTrust's Retina® Network Security Scanner scans devices to detect for this vulnerability.
- 30541 - Microsoft Internet Explorer MSHTML NULL_IMPORT_DESCRIPTOR (Zero-Day)
- 30542 - Microsoft Internet Explorer MSHTML NULL_IMPORT_DESCRIPTOR (Zero-Day) - x64
Status:
2013-09-17 - Public advisory released
0 nhận xét:
Đăng nhận xét