Finally stopped using Internet Explorer? Good! But, now it’s time to completely delete it from your computer, too.
Security researcher John Page has discovereda new security flawthat allows hackers to steal Windows users’ data thanks to Internet Explorer. The craziest part: Windows users don’t ever even have to open the now-obsolete web browser for malicious actors to use the exploit. It just needs to exist on their computer.
“Internet Explorer is vulnerable to XML External Entity attack if a user opens a specially crafted .MHT file locally,” writesPage. “This can allow remote attackers to potentially exfiltrate Local files and conduct remote reconnaissance on locally installed Program version information.”
Basically, what this means is that hackers are taking advantage of a vulnerability using .MHT files, which is the file format used by Internet Explorer for its web archives. Current web browsers do not use the .MHT format, so when a PC user attempts to access this file Windows opens IE by default.
To initiate the exploit, a user simply needs to open an attachment received by email, messenger, or other file transfer service.
“[For] example, a request for "c:\Python27\NEWS.txt" can return version information for that program,” Page explains. “Upon opening the malicious '.MHT' file locally it should launch Internet Explorer. Afterwards, user interactions like duplicate tab 'Ctrl+K' and other interactions like right click 'Print Preview' or 'Print' commands on the web-page may also trigger the XXE vulnerability.”
The exploit has been tested using the last version of Internet Explorer, IE 11. It affects Windows 7, Windows 10, and Windows Server 2012 R2 users.
Most worrisome, according to Page, is that Microsoft told him that it would just “consider” a fix in a future update. The security researcher says he contacted Microsoft in March before now going public with the issue.
As ZDNetpoints out, while Internet Explorer usage makes upless than 10 percent of the web browser market, it doesn’t particularly matter in this case as the exploit just requires a user to have the browser on their PC.
Earlier in 2019, Microsoft cybersecurity expert Chris Jackson urged anyone still using Internet Explorer to finally give it up. The company officially discontinued its former flagship web browser in 2015.
Copyright © 2023 Powered by
Internet Explorer exploit is trouble even if you never use the browser-燕尔新婚网
sitemap
文章
6
浏览
31
获赞
2392
EU is investigating Apple Pay and App Store for breaking competition rules
The European Commission has launched two formal investigations into Apple's business practices overApple launches iOS 18.2 developer beta (the real AI update)
Apple's iOS 18.1, which will become widely available in a few days, brings a timid list of Apple Int5 apps to add AI to your older devices
The likes of Apple and Google are building powerful new AI features straight into their latest operaBest headphones deal: Grab refurbished Bose QuietComfort Headphones for just $143.10
SAVE $205.90:As of Nov. 20, get a pair of refurbished Bose QuietComfort Headphones at Bose for $143.Good news everyone, Logan Paul doesn't actually think the Earth is flat
Logan Paul is many things, but thankfully he is not a flat Earther. In a 50-minute, 2-second mockumeTrump confuses ISIS with Saudi Arabia at debate
Donald Trump made a blunder during the final presidential debate Wednesday, apparently confusing theWho is this mysterious doctor behind Trump and what does he want?
Donald Trump's rallies attract all sorts of people -- including, apparently, doctors in full uniformQuiz: Can you find the end of Donald Trump's sentence?
It can be tortuous to find the end of Donald Trump's wandering sentences, but it can also provide aYes, you can teach your cat to fetch
It's not just dogs who love the art of retrieval. Quite a few cat owners report that their feline frBlack Friday vs. Cyber Monday 2024: Which day has better deals?
UPDATE: Nov. 19, 2024, 1:15 p.m. EST This post has been updated with information about Black FridayBest streaming deal: Get the Amazon Fire TV Cube for $99.99
SAVE $40: As of Nov. 13, get an Amazon Fire TV Cube at Amazon for $99.99, down from its usual price7 Vines that totally ripped the piss out of British politicians
Vine is dead.SEE ALSO: Vine's last tweet may have told us the end was neariPhone 12 might look like an iPad Pro, and the HomePod could shrink
Apple is reportedly giving its iPhone lineup a complete revamp. According to Bloomberg, unnamed souScottish beauty blogger has wise skincare advice for older women
LONDON -- Beauty vlogging is overwhelmingly directed at millennials and their successors. But that dScientists think the common cold may at last be beatable
Time and again, Martin Moore’s children get sick with a cold. He hauls them to their doctor, w