Finally stopped using Internet Explorer? Good! But, now it’s time to completely delete it from your computer, too.
Security researcher John Page has discovereda new security flawthat allows hackers to steal Windows users’ data thanks to Internet Explorer. The craziest part: Windows users don’t ever even have to open the now-obsolete web browser for malicious actors to use the exploit. It just needs to exist on their computer.
“Internet Explorer is vulnerable to XML External Entity attack if a user opens a specially crafted .MHT file locally,” writesPage. “This can allow remote attackers to potentially exfiltrate Local files and conduct remote reconnaissance on locally installed Program version information.”
Basically, what this means is that hackers are taking advantage of a vulnerability using .MHT files, which is the file format used by Internet Explorer for its web archives. Current web browsers do not use the .MHT format, so when a PC user attempts to access this file Windows opens IE by default.
To initiate the exploit, a user simply needs to open an attachment received by email, messenger, or other file transfer service.
“[For] example, a request for "c:\Python27\NEWS.txt" can return version information for that program,” Page explains. “Upon opening the malicious '.MHT' file locally it should launch Internet Explorer. Afterwards, user interactions like duplicate tab 'Ctrl+K' and other interactions like right click 'Print Preview' or 'Print' commands on the web-page may also trigger the XXE vulnerability.”
The exploit has been tested using the last version of Internet Explorer, IE 11. It affects Windows 7, Windows 10, and Windows Server 2012 R2 users.
Most worrisome, according to Page, is that Microsoft told him that it would just “consider” a fix in a future update. The security researcher says he contacted Microsoft in March before now going public with the issue.
As ZDNetpoints out, while Internet Explorer usage makes upless than 10 percent of the web browser market, it doesn’t particularly matter in this case as the exploit just requires a user to have the browser on their PC.
Earlier in 2019, Microsoft cybersecurity expert Chris Jackson urged anyone still using Internet Explorer to finally give it up. The company officially discontinued its former flagship web browser in 2015.
Copyright © 2023 Powered by
Internet Explorer exploit is trouble even if you never use the browser-拍板定案网
sitemap
文章
53
浏览
961
获赞
7725
GoFundMe bans anti
GoFundMe is cracking down on anti-vaxxers.The popular fundraising website says it will no longer allPhoto gallery: 'Sailor Moon' fans bring the superhero to a rave in Brooklyn
"In the name of the moon... we'll plur with you! Come PLUR OR COME PURR!" read the online invite toTesla now lets you control your car with Apple Shortcuts
Apple Shortcuts have just become a bit more useful to Tesla owners. In the latest version (4.24.0) oApple iPhone 15 USB
We thought it would be coming, but now it's finally confirmed: The iPhone 15 is getting a USB-C portApple could debut its new laptop chip in a Macbook Pro this year
A few weeks after Apple announced it would start developing its own silicon chip for Mac computers,Threads search is now widely available
Threads is still missing plenty of important features, but Search is no longer one of them. At leastGoogle Pixel 8 unboxing videos leak before event
We know when Google's big Pixel 8 event is supposed to take place. We even know roughly what to expeThe iPhone 15 Pro Max may not be easy to get this year. Here's why.
Demand plus production delays means it might be tougher for Apple users to get their hands on the iPPrince William and Kate Middleton are the king and queen of draught beer
Prince William and Kate Middleton just proved that they, like many of their fellow Britons, love a gTinder rolls out Relationship Types and pronouns features
On the heels of releasing its new Relationship Goals feature, Tinder is now rolling out a couple morSpeaker of the House vote memes and jokes: Kevin McCarthy gets roasted online amid 6 failed votes
Congress is a mess. But at least the memes are good. If you're not up on your political news, Republ'Gimme The Mic' is TikTok's new music competition
TikTok is entering the music competition space with "Gimme The Mic.""Gimme The Mic" is a global compForget Zoom. Here's how to make group video calls on Snapchat instead.
If you're trying to round up your friends or family for a good ol' video chat sesh, look no further'Gimme The Mic' is TikTok's new music competition
TikTok is entering the music competition space with "Gimme The Mic.""Gimme The Mic" is a global compMicrosoft ends free upgrade from Windows 7 to 11
Microsoft is ending its upgrade offer from Windows 7 or 8 to Windows 10 or 11, the company recently