New workaround for the IE CSS Exploit

Status
Not open for further replies.

bogdan

Level 1
Thread author
Jan 7, 2011
1,362
This vulnerability requires an attacker to provide a CSS style sheet that includes a reference to itself with an @import command. When Internet Explorer tries to load this recursive style sheet, it corrupts memory in a way that could be exploited for arbitrary code execution.

The old workaround was to enable EMET to block aspects of the known exploits from being successful.
The new one is much easier to apply. It only involves the installation of an MSI package (Microsoft "FixIt") - link

source
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top