Hot exploit for Internet Explorer

Again one of these interesting IE exploits, according to this advisory.

It has again all the good ingredients for a nice security hole:

  • It runs on Windows
  • It runs on Internet Explorer
  • It is remotely exploitable  (and there are public exploits)
  • It executes arbitrary code  (with corresponding consequences for people, who thanks to the many applications, run their daily business as local administrator of their machine).

 The advisory from FrSIRT is actually quite descriptive, but I highly doubt many users will read that, or even heed the advice to continue using IE.

At least such catastrophic security holes haven't discovered on other web browsers, and neither other operating systems.

Hony soit qui mal y pense....