| « New GMail Security | Multiple BSD Distributions dtoa.c (pdtoa.c) and 'gdtoa/misc.c' Memory Corruption Vulnerability » |
Details about the targeted attack on Google (and 34 other firms) now include the use of an IE 0-day (CVE-2010-0249) in addition to known Acrobat vulnerabilities. Microsoft has released a related advisory and public exploit code is now available. This exploit will be increasingly used in drive-by attacks by malware authors. A patch is expected to be available on the next "patch Tuesday" (no out of band patch is expected to be released).
Details:
http://www.microsoft.com/technet/security/advisory/979352.mspx
©2010 by Priveon, Inc.