New workaround for the IE CSS Exploit

Status
Not open for further replies.

bogdan

Level 1
Thread author
Jan 7, 2011
1,362
44
32
40
Bucharest, RO
malwaretips.com
This vulnerability requires an attacker to provide a CSS style sheet that includes a reference to itself with an @import command. When Internet Explorer tries to load this recursive style sheet, it corrupts memory in a way that could be exploited for arbitrary code execution.

The old workaround was to enable EMET to block aspects of the known exploits from being successful.
The new one is much easier to apply. It only involves the installation of an MSI package (Microsoft "FixIt") - link

source
 
Status
Not open for further replies.