Email this article   Print article 


Internet Explorer Zero-Day Threat Linked To Java

By Ken Presti
September 18, 2012    4:37 PM ET

Page 2 of 2

During the interim, Microsoft is recommended two stopgap measures. The first recommendation involves setting security levels for both the Internet zone and the local zone to high. The objective is to discontinue ActiveX controls and Active Scripting on the machine.

"Running the Internet zone like that is generally fine and a good idea," said nCircle's Storms. "But putting the local zone into a high-security mode generally comes with some unexpected consequences. Some business applications may not function correctly with that setting because they generally use things like ActiveX scripting."

Microsoft's second piece of advice is to use the company's Enhanced Mitigation Experience Toolkit (EMET), which it believes could block most of the attacks without adverse impacts elsewhere on the system. According to BeyondTrust’s Maiffret, preliminary testing indicates that this countermeasure is successful in at least some scenarios.

And, prompt response is advised. With the exploit now integrated into Metasploit and similar kits, the attack vector becomes much more inviting to a much wider range of cyber criminals.

"The last few zero days we've seen have been quickly added into the everyday exploit toolkits," said Maiffret. "When these things are used in targeted attacks, they typically impact a limited number of companies. But, once they are in the kits, the fallout can be a lot worse. We're now in a situation where basically anyone can do it. It's point and click easy."

PUBLISHED SEPT. 18, 2012

This story was updated on Sept. 18, 2012, at 5:00 p.m. PST, in order to note that Yunsun Wee, director of Microsoft Trustworthy Computing, issued a statement Tuesday afternoon indicating that a patch would be available "in the next few days."

<< Previous | 1 | 2

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Tech 10: Hot Antivirus Alternatives For 2013

CRN identifies 10 vendors that have developed innovative ways to detect malware and analyze threats to better protect corporate networks. They take a giant step beyond traditional signature technologies.

10 Emerging Security Technologies Gaining Interest, Adoption

Despite some security defenses being only in their infancy, they are attracting interest for addressing BYOD issues, cloud security concerns and stolen account credentials. Here's a look at some of the top new security areas gaining industry interest.

5 Government Intelligence Facilities You've Never Heard Of

One facility has been around since the dawn of space exploration, while other buildings are still in construction. But, they all have serious data analysis and surveillance support activities associated with them.

  More Slide Shows




Related Videos
Loading...