Finally stopped using Internet Explorer? Good! But, now it’s time to completely delete it from your computer, too.
Security researcher John Page has discovereda new security flawthat allows hackers to steal Windows users’ data thanks to Internet Explorer. The craziest part: Windows users don’t ever even have to open the now-obsolete web browser for malicious actors to use the exploit. It just needs to exist on their computer.
“Internet Explorer is vulnerable to XML External Entity attack if a user opens a specially crafted .MHT file locally,” writesPage. “This can allow remote attackers to potentially exfiltrate Local files and conduct remote reconnaissance on locally installed Program version information.”
Basically, what this means is that hackers are taking advantage of a vulnerability using .MHT files, which is the file format used by Internet Explorer for its web archives. Current web browsers do not use the .MHT format, so when a PC user attempts to access this file Windows opens IE by default.
To initiate the exploit, a user simply needs to open an attachment received by email, messenger, or other file transfer service.
“[For] example, a request for "c:\Python27\NEWS.txt" can return version information for that program,” Page explains. “Upon opening the malicious '.MHT' file locally it should launch Internet Explorer. Afterwards, user interactions like duplicate tab 'Ctrl+K' and other interactions like right click 'Print Preview' or 'Print' commands on the web-page may also trigger the XXE vulnerability.”
The exploit has been tested using the last version of Internet Explorer, IE 11. It affects Windows 7, Windows 10, and Windows Server 2012 R2 users.
Most worrisome, according to Page, is that Microsoft told him that it would just “consider” a fix in a future update. The security researcher says he contacted Microsoft in March before now going public with the issue.
As ZDNetpoints out, while Internet Explorer usage makes upless than 10 percent of the web browser market, it doesn’t particularly matter in this case as the exploit just requires a user to have the browser on their PC.
Earlier in 2019, Microsoft cybersecurity expert Chris Jackson urged anyone still using Internet Explorer to finally give it up. The company officially discontinued its former flagship web browser in 2015.
Copyright © 2023 Powered by
Internet Explorer exploit is trouble even if you never use the browser-拍板定案网
sitemap
文章
848
浏览
19
获赞
272
Amazon's proposed federal anti
Amazon is worried about its customers getting ripped off — well, that and being held legally rTesla finally lets you fully control windshield wipers from the steering wheel
Tesla's user interface can sometimes feel lacking, partially due to the sparse physical controls inMore than 100,000 hacked ChatGPT accounts are being sold on dark web marketplaces
There's no doubt about it: ChatGPT, the AI chatbot from OpenAI, is extremely popular and has seeming'Jenna Ortega reveals' is the latest meme taking over Twitter
Wednesdaystar Jenna Ortega clarifies that all those tweets you've been seeing on your timeline are mApple gives students and teachers free AirPods with purchase of Mac or iPad
AirPods are cool. Free AirPods are even cooler. Apple is giving away a free pair of AirPods for studiOS 17 moves the button to end phone calls
Phone calls on iPhones are about to get slightly more annoying.By "slightly," I mean veryslightly. THere's how to stream Xbox games directly to Discord
Discord and Microsoft are taking the next logical step in their Xbox-related partnership: StreamingReddit bids farewell to third
Despite Reddit users' protests, Reddit has moved forward with its decision to charge developers of tFacebook criticized by Free Press for empty PR response to ad boycott
In the face of mounting advertiser pressure over its handling of hate speech, Mark Zuckerberg todayTucker Carlson's Trump interview doesn't have 230 million video views on X
On Wednesday night, former Fox News host Tucker Carlson interviewed former president Donald Trump onThe soft life and quiet quitting: How one led to the other
Before quiet quitting took corporate America by storm, Black women were quietly quitting their arduoFake 'Zelda' posters have people thinking a Netflix series is coming. It's not.
Fans of Nintendo's (highly popular) fantasy game, The Legend of Zelda, will be disappointed.A seriesCreatively, a new job platform, launches to help designers and other creatives find work
For designers, illustrators, and photographers, LinkedIn just doesn't cut it. That's why CreativelyThe EU will require all smartphones to have replaceable batteries by 2027
The European Union is officially requiring all smartphones to have replaceable batteries by 2027. ThHow to delete your Amazon account
Amazon's Prime Day kicks off Tuesday, July 11, and runs through July 12. That means deals and lots o