Hackers seize Internet Explorer bug, no patch for Windows XP

A Guy

Righteous Dude
Guru
VIP
SF Team
Local time
1:43 AM
Messages
33,043
Location
Bay Area
IE 6 to 11 puts Win PCs at risk of hijacking, fix coming – but not for dead OSes

Microsoft has warned of a new flaw in all available versions of its Internet Explorer web browser.

Vulnerability CVE-2014-1776, to give the problem its formal name, allows miscreants to hijack at-risk Windows computers. It's all due to “the way Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated”, the software giant explained on Saturday.

The flaw means the browser “may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer".

"Microsoft is aware of limited, targeted attacks that attempt to exploit [this] vulnerability in Internet Explorer," the software giant added.

"An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.”

Internet Explorer 6 through 11 are all at risk, on all current versions of Windows from Vista to 8 and Windows Server 2003 to 2012 R2. The bug is understood to be present in IE on Windows XP, although that operating system is no longer supported.

Source

A Guy
 

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
I hope I dont get attacked. Do you think this is worse than Heartbleed? IE has a larger market share than websites that use OpenSSL. Good thing I have both a good antivirus and antimalware.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Vostro 400/Dell XPS 8700(Slightly Customized for me by Dell)/Toshiba Satellite T135
OS
Windows 7 Professional 32-bit/Windows 8 64-bit/Win7 Pro64-bit
CPU
Intel Core 2 Quad Q6600/Intel Core i7 4790/Intel Pentium
Memory
2GB/16GB/4GB
Graphics Card(s)
Intel G33/G31 Express(Vostro)/NVIDIA GeForce GTX 745(XPS)
Monitor(s) Displays
HP 2009m(Vostro)/ViewSonic VX2250wm-LED(XPS)
Screen Resolution
1600x900(Vostro)/1920x1080(XPS)
Hard Drives
Seagate ST3160815AS(Vostro)/Western Digital Blue(Satellite)
External:
Western Digital My Passport 0748
Samsung HM121HC
Keyboard
Dell L100)(Vostro)/Dell KB2133p(XPS)
Mouse
Dell M-UAV-DEL8(XPS)
Internet Speed
100 Mbit/s(Only when IPTV is plugged out)
Antivirus
Avast, Malwarebytes PRO
Browser
Internet Explorer 11
Other Info
Note: Names with slashes between two different parts mean that the left is my old desktop and the right is my old laptop and the middle is my new desktop.(Unless specified)
Ping is horrible for servers overseas in US and Europe.
New laptop:LG Gram(Not available in US) Processor:Intel Core i3 4th Gen Ultra Low Power RAM:4GB Hard Drive:SK Hynix OEM MSATA or M.2 Graphics:Intel HD

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
I heard this too. I am going to use FF or higher from now on, the patch is never happening to WinXP anymore. But I could be wrong.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows Vista Business 32bit
CPU
Intel(R) Pentium(R) Daul CPU E2220 @ 2.40GHz
Memory
2.00GB
Graphics Card(s)
Intel Pentium
Sound Card
AudioESP SoundMAX
Monitor(s) Displays
Dell
Hard Drives
ST380815AS ATA Device 80 GB
Keyboard
Logitech Keyboard
Mouse
Logitech Mouse
Internet Speed
44 Mbps
Antivirus
AVG Free
Looks there's a workaround the time to wait for a patch...just saw that today!:o

One workaround, which is listed towards the bottom of Microsoft's alert, includes disabling VGX.dll, which is responsible for rendering of VML (Vector Markup Language) code in webpages. VML is only infrequently used on the web, Kandek adds, so disabling it in IE is the best way to prevent exploitation. To deregister it, type in the following:

0-Day Vulnerability in Internet Explorer Threatens Windows XP
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional SP1 - x64 [Non-UEFI Boot]
CPU
Ivy Bridge Core i5 3570K (Delidded)
Motherboard
Asus P8Z77-V LE PLUS
Memory
G.Skill "Ares" DDR3 PC3-12800 - 1600MHz (16Gb)
Graphics Card(s)
Asus Dual-RX480-O4G
Sound Card
Creative Sound Blaster Z w/5.1 sound system
Monitor(s) Displays
Asus IPS 23"
Screen Resolution
16/9
Hard Drives
Internal:
500Go Sata 6Gb/s (x2)
500Go Sata 3Gb/s (x2)
SSD 60Go Sata 6Gb/s
PSU
In Win C 900W Series 80+ Platinum
Case
Thermaltake Chaser A71
Cooling
Custom Water Cooling Loop
Keyboard
Cooler Master QuickFire XTi
Mouse
Razer Imperator 2012 (4G)
Antivirus
MSE
Browser
IE 11.0.xxx Rtm
Other Info
"Raid0" with Intel Smart Response Technology (HDD/SSD)
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
It's pretty much the same warning that's getting blown out of proportion by the anti-MS and anti-IE crowd. You gotta be as smart as a rock to fall for the typical scams used to get people to click on links that are infected.

Mitigating Factors:
  • By default, Internet Explorer on Windows Server 2003, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2 runs in a restricted mode that is known as Enhanced Security Configuration. This mode mitigates this vulnerability.
  • By default, all supported versions of Microsoft Outlook, Microsoft Outlook Express, and Windows Mail open HTML email messages in the Restricted sites zone. The Restricted sites zone, which disables script and ActiveX controls, helps reduce the risk of an attacker being able to use this vulnerability to execute malicious code. If a user clicks a link in an email message, the user could still be vulnerable to exploitation of this vulnerability through the web-based attack scenario.
  • An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  • In a web-based attack scenario, an attacker could host a website that contains a webpage that is used to exploit this vulnerability. In addition, compromised websites and websites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these websites. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes users to the attacker's website.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
Things I can and can not do any thing about.
Can't Do'S
1. I can not stop attackers from trying to get into my system.
2. I can not use a browser that is 100% safe all the time.
3. I can not update my browser and security programs faster than the updates are out (published).
4. I can not slow down the bad guys from coming up with new ways to attack my system.
** Their are many more things I can not do. Add to the list as you see fit.
------------------------------------
Can DO's
1. I can read security news like we are doing now. A Guy and others post many of them. Having a basic knowledge of what the bad guys are up to will help.
2. I can keep all my security programs updated often. Once a week is not enough.
3. I can check other programs such as Adobe, Flash ect. and make sure they have their security updates.
4. I can do security scans for infections, PUP, Adware ect. even when their are no signs of a problem. I can have a problem and not know it.
5. I can choose not to open goofy emails, Instant Messages ect.
I can't believe people still do this after a decade of warnings.
6. I can shut down the computer when a web page starts to act crazy and doing a lot of things I didn't ask for and then run security scans.
7. I can choose not to use P2P/Torrents.
8. I can choose who gets my email address to some degree.
9. I can choose who gets my personnel information to some degree.
10. I can choose how the keyboard and mouse are used and when.
This is the big one: If I choose to use the mouse and keyboard in a unsafe way then I will get in trouble quickly.

Note:
If they ever did create programs to protect my system 100% from the bad guys we all would have it.
Now they would have to create a program to protect me and my system from me. Only I can protect me and my system from me.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Kudos Layback Bear!
a041.gif
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Thank you Jacee.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Things I can and can not do any thing about.
Can't Do'S
1. I can not stop attackers from trying to get into my system.
2. I can not use a browser that is 100% safe all the time.
3. I can not update my browser and security programs faster than the updates are out (published).
4. I can not slow down the bad guys from coming up with new ways to attack my system.
** Their are many more things I can not do. Add to the list as you see fit.
------------------------------------
Can DO's
1. I can read security news like we are doing now. A Guy and others post many of them. Having a basic knowledge of what the bad guys are up to will help.
2. I can keep all my security programs updated often. Once a week is not enough.
3. I can check other programs such as Adobe, Flash ect. and make sure they have their security updates.
4. I can do security scans for infections, PUP, Adware ect. even when their are no signs of a problem. I can have a problem and not know it.
5. I can choose not to open goofy emails, Instant Messages ect.
I can't believe people still do this after a decade of warnings.
6. I can shut down the computer when a web page starts to act crazy and doing a lot of things I didn't ask for and then run security scans.
7. I can choose not to use P2P/Torrents.
8. I can choose who gets my email address to some degree.
9. I can choose who gets my personnel information to some degree.
10. I can choose how the keyboard and mouse are used and when.
This is the big one: If I choose to use the mouse and keyboard in a unsafe way then I will get in trouble quickly.

Note:
If they ever did create programs to protect my system 100% from the bad guys we all would have it.
Now they would have to create a program to protect me and my system from me. Only I can protect me and my system from me.

Good post!:cool:
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
MSI PE60 6QE
OS
Win 10 Pro x64, Win 7 Pro x64
CPU
Intel Core i7-6700HQ Skylake
Motherboard
MSI MS-16J5
Memory
16gb Crucial DDR4
Graphics Card(s)
NVIDIA GeForce GTX 960M 2 GB
Screen Resolution
1920 x 1080
Hard Drives
Samsung 850 EVO 250 GB M.2 SSD (MZ-N5E250BW)
HGST 1TB @7200 RPM HTS721010A9E630
Case
Plastic
Keyboard
Got one...
Mouse
Yep, one of those too.
Internet Speed
FIOS 75/75
Antivirus
Defender
Browser
Chrome/FFox/Ex-PLODE-r/(L)Edge
Other Info
Defender, Custom Hosts, uBlock, regular backups w/ Macrium (Free)
Thank you Urthboundmisfit.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Back
Top