Advertisement
Promo

Security threats Toolkit

Exploit targets IE7 hole patched a week ago

Elinor Mills CNET News

Published: 18 Feb 2009 09:17 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cybercriminals are exploiting a critical hole in Internet Explorer 7 that was patched a week ago by Microsoft, security firm Trend Micro warned on Tuesday.

The malicious code, which Trend Micro named 'XML_DLOADR.A', is hidden in a Word document. On unpatched systems, when the file is opened, an ActiveX object automatically accesses a website to open a backdoor that installs a .DLL (dynamic link library) file that can steal information, according to a Trend Micro blog entry. The code sends stolen data to another web address via port 443, Trend Micro said.

As a result of the back door, "anybody can run commands on the affected system", said Jamz Yaneza, a senior threat analyst and researcher at Trend Micro.

Microsoft released a security patch for the vulnerability, and others, a week ago. The vulnerability arises from the browser's improper handling of errors when attempting to access deleted objects.

"It looks like a proof of concept or targeted attack," Yaneza said. The exploit is similar to politically motivated attacks that were seen before the Olympics last year in which PDF files and Word documents contained exploit code and automatically connected computers to malicious websites, he said.

It appears that the site directed to is in China and there is Chinese terminology in the code, according to Yaneza. That and the fact that the 50th anniversary of the Tibetan uprising is approaching, on 10 March, suggests that this attack could be politically motivated as well, he said.

"People need to speed up how they patch their [operating systems], or turn on auto update in Windows," Yaneza said.

Credit: New exploit targets IE 7 hole patched last week from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
47 out of 47 people found this useful


Full Talkback thread

1 comment

  1. ACTIVEX ator1940

Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters