Microsoft Releases Out-of-Band Advisory for all Versions of Internet Explorer

Published: 2013-09-17. Last Updated: 2013-09-17 18:28:56 UTC
by John Bambenek (Version: 1)
5 comment(s)

Microsoft just released an advisory on an Internet Explorer vulnerability that would allow for remote execution.  The report references public availability of details of his vulnerability.  The long story short, a targetted attack that gets a user to view a malicious webpage (or malicious content on an otherwise safe webpage) could lead to memory corruption that could execute arbitrary code with the permissions of the logged in user.  Two suggested actions are provided by Microsoft, apply the FixIt provided by Microsoft or deploy EMET 3.0/4.0 which provides generalized protection of memory (and probably not a bad idea to deploy anyway).  Note, the FixIt ONLY applies to 32-bit versions of Internet Explorer.

This post will be updated with more details as the situation warrants.

--
John Bambenek
bambenek \at\ gmail /dot/ com
Bambenek Consulting

5 comment(s)

Comments

Does anyone know what the FixIt actually does? I'd like to have the option to deploy this system wide via GP or something.
Oops, look first, ask questions second. The FixIt downloads an msi file, so it's deployable. I still don't know what it does, though...
The Fixit is described in detail here: http://blogs.technet.com/b/srd/
2013-09-17 1500 downloaded EMET 4.0 and installed it. Used 'Recommended' config (ie ticked MS products, et al).
Executed IE. It immediately crashed: "Program failed." Clicked "Cancel". Cancel failed. Clicked "X". X failed.
Using Processes Explorer, killed process. Kill Process worked as expected.
Executed IE a second time. Same result.
Using Control Panel, uninstalled EMET and EMET 4.0. Executed IE a third time. IE came up as expected. Advised client of greater risk without EMET. Client said, "Give me my (working) IE (with all my Favorites) and my Boggle".
Granted you only hear the "bad" but EMET 4.0 seems problematic for many folks. I'd try using EMET 3.5 Tech Preview and see if things stabilize. Nice feature set, but I suspect EMET 4.0 was released a bit too soon. YMMV

Diary Archives