ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Internet Explorer 9 haunted by 'critical' security vulnerabilities

By | October 11, 2011, 12:03pm PDT

Summary: Microsoft fixes drive-by download flaws in the latest version of its dominant Internet Explorer browser and warns that exploits could emerge within 30 days.

Microsoft’s shiny new Internet Explorer 9 browser contains critical security vulnerabilities that expose users to drive-by download attacks, the company warned today.

The IE warning highlights this month’s batch of security patches from Microsoft where the company shipped eight security bulletins (two critical, six important) to cover gaping holes in Internet Explorer, .NET Framework & Silverlight, Microsoft Windows, Microsoft Forefront UAG and Microsoft Host Integration Server.follow Ryan Naraine on twitter

According to Microsoft, the IE vulnerabilities could be exploited if a user simply surfs to a maliciously rigged website.

The IE update (MS11-081), available for all users or Microsoft Windows and all versions of Internet Explorer, covers at least eight documented security holes in the world’s most widely used browser.

The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

The update fixes the vulnerabilities by modifying the way that Internet Explorer handles objects in memory and the way that Internet Explorer allocates and accesses memory, Microsoft explained.

Microsoft is urging all Windows users to treat this with the utmost priority because of the likelihood of reliable exploit code within 30 days.  Malicious hackers typically reverse-engineer the patches to identify the flaws and write exploits immediately to launch malware attacks.

The second “critical” update (MS11-078) addresses a vulnerability in .NET Framework and Microsoft Silverlight that could expose users to remote code execution attacks.

The vulnerability could allow remote code execution on a client system if a user views a specially crafted Web page using a Web browser that can run XAML Browser Applications (XBAPs) or Silverlight applications. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. The vulnerability could also allow remote code execution on a server system running IIS, if that server allows processing ASP.NET pages and an attacker succeeds in uploading a specially crafted ASP.NET page to that server and then executes the page, as could be the case in a Web hosting scenario. This vulnerability could also be used by Windows .NET applications to bypass Code Access Security (CAS) restrictions.

Microsoft warns that a victim could be exploited if he/she browses to a malicious webpage with aSilverlight-enabled browser.

As with the IE patch, Microsoft exploits to see “reliable exploits” for Silverlight 3 over the next 30 days.

The company also raised an alert for a third bulletin (MS11-077) that covers at least four documented vulnerabilities in Windows kernel-mode drivers (Win32k.sys).

The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted font file (such as a .fon file) in a network share, a UNC or WebDAV location, or an e-mail attachment, the company explained.

The security update addresses the vulnerabilities by correcting the way that the Windows kernel-mode drivers validate input passed from user mode, handle the TrueType font type, allocate the proper buffer size before writing to memory, and manage kernel-mode driver objects.

This month’s Patch Tuesday batch also covers five privately reported vulnerabilities in Forefront Unified Access Gateway (UAG). The most severe of these vulnerabilities could allow remote code execution if a user visits an affected Web site using a specially crafted URL.

It also provides fixes for a solitary flaw in the Microsoft Windows Ancillary Function Driver (AFD) and two publicly disclosed vulnerabilities in Host Integration Server.

The Host Integration Server vulnerabilities could allow denial of service if a remote attacker sends specially crafted network packets to a Host Integration Server listening on UDP port 1478 or TCP ports 1477 and 1478.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

47
Comments

Join the conversation!

Just In

sdfds
jywhy888 7th Mar
Wholesale Toys Wholesale Banner http://www.chinawholesaletown.com/wholesale-Flash-Gift/ World Cup Products
Manicure Set Garden Decorations http://www.chinawholesaletown.com/wholesale-Tellurion/ Umbrella
Lunch Box Wholesale Mouse http://www.chinawholesaletown.com/wholesale-Clothes-Rack/ Wedding Favors
Wine Set Industrial Supplies http://www.chinawholesaletown.com/wholesale-Pen-Holder/ Scarf
Wholesale Sticker Wholesale Stationery http://www.chinawholesaletown.com/wholesale-Waterproof-Case/ Poncho
Wholesale Clothing Wholesale Flag http://www.chinawholesaletown.com/wholesale-Wine-Set/ Ruler
Wholesale Flashlight Wholesale Helmet http://www.chinawholesaletown.com/wholesale-MP3---MP4---MP5-Player/ lable
Wholesale Wallet Writing Instrument http://www.chinawholesaletown.com/ Baby Products Suppliers
Wholesale Lanyard Wholesale Pin http://www.chinawholesaletown.com/ Book Light
Lady Beauty Care Wholesale Earphone http://www.chinawholesaletown.com/wholesale-Silicone/ Earphone
Electroluminescent Wholesale Gift Bags http://www.chinawholesaletown.com/wholesale-Solar-Products/ Fishing Supplies
Wholesale Badge Advertising Material http://www.chinawholesaletown.com/wholesale-Stuffed-Animals/ Vase
Wholesale Speakers Pen Holder http://www.chinawholesaletown.com/wholesale-Racks/ Furniture
Wholesale Coaster Wholesale Magnifier http://www.chinawholesaletown.com/wholesale-Camera/ Mirror
Wholesale Compass Wholesale Whistle http://www.chinawholesaletown.com/ Audio Video Equipment
Poncho Raincoat Wholesale Mp3 http://www.chinawholesaletown.com/wholesale-Glasses/ Mobile Phone
Health Care Products Wholesale Hardware Tools http://www.chinawholesaletown.com/wholesale-Recorder-Pen/ Pin
Wholesale Flag Wholesale Binoculars http://www.chinawholesaletown.com/wholesale-Business-Gift/ China Wholesale
Audio Video Equipment Coca Cola Gifts http://www.chinawholesaletown.com/wholesale-Sport-Items/ Coin Bank
Wholesale Mouse Wholesale Puzzle http://www.chinawholesaletown.com/wholesale-Fan/ Scissors
Wholesale Calendar Wholesale Racks http://www.chinawholesaletown.com/wholesale-Apron/ Jewelry
Wholesale Umbrella Electroluminescent http://www.chinawholesaletown.com/wholesale-Entertainment/ First Aid Kit
Wholesale Whistle Wholesale Scale http://www.chinawholesaletown.com/wholesale-Pen/ Clothes Rack
Wholesale Towel Entertainment Supplies http://www.chinawholesaletown.com/wholesale-Dartboard/ Dartboard
Wholesale Glasses Fishing Supplies http://www.chinawholesaletown.com/wholesale-Binoculars/ USB Flash Drive
Reflective Safety Vest Wholesale Pom Poms http://www.chinawholesaletown.com/wholesale-Ashtray/ Watch
Bottle Opener Wholesale Mobile Phone http://www.chinawholesaletown.com/wholesale-Kitchenware/ Pedometer
Wholesale Banner Wholesale Clap Hands http://www.chinawholesaletown.com/wholesale-Radio/ Calculator
Wholesale Clap Hands Wholesale USB Products http://www.chinawholesaletown.com/wholesale-Cup/ Banner
Garden Decorations Wholesale Speakers http://www.chinawholesaletown.com/wholesale-Bag/ Frisbee
Wholesale Cards Sport Support Products http://www.chinawholesaletown.com/wholesale-Helmet/ Speakers
Wholesale Halloween Gift Men Beauty Care http://www.chinawholesaletown.com/wholesale-Book-Light/ Pen Holder
Wholesale Bracelet Silicone Products http://www.chinawholesaletown.com/wholesale-Medicine-Instrument/ Fan
Christmas Gifts Outdoor Leisure Products http://www.chinawholesaletown.com/wholesale-Money-Bank/ Recorder Pen
Wholesale Scissors Wholesale Lighter http://www.chinawholesaletown.com/wholesale-Jewelry/ Heating Products
Wholesale Candle Wholesale Golf Products http://www.chinawholesaletown.com/wholesale-Clothing/ Stuffed Animals
Wholesale Lighter Wholesale Stress Ball http://www.chinawholesaletown.com/wholesale-Water-Bottle/ Cap
Oh, I thought these days were behind us...
0 Votes
+ -
@Jeremy-UK
I know. MS, Google, Mozilla, they have their issues, but they're patched and that's that.

Why do they keep making a big deal about all these browsers?
0 Votes
+ -
I'll tell you why...
Splork 11th Oct
@William Farrell

Look for Ed Bott's post about "Your Browser Matters" where MS has a web site that grades your browser's "security level."

Guess what browser gets all A's. It's a freakin joke.
0 Votes
+ -
You told us why
ScorpioBlue 11th Oct
And IE gets a .... .... ?

(silence in the background...)

wink
0 Votes
+ -
Agreed
jscott418 12th Oct
@William Farrell This is nothing new, Chrome just had some bad ones just recently. Firefox too. I guess IE still get's picked on. You have your fanboys for all the browsers. I just do the updates and don't worry a whole lot about what might happen.
@Jeremy-UK Not as long as every windows app requires admin rights to install. Hand over the computer keys...
Oh, I thought these days were behind us...

So did I.

LOL... grin
@ScorpioBlue

Don't you have a loaded handgun you could go clean?
  • Flagged
@Hallowed are the Ori

Don't you have a toilet you can stick your head in?
@Jeremy-UK
Best browser - Chrome on a Mac...
@Jeremy-UK

No, Microsoft is still cranking out the code ...
0 Votes
+ -
sdfds
jywhy888 7th Mar
Wholesale Toys Wholesale Banner http://www.chinawholesaletown.com/wholesale-Flash-Gift/ World Cup Products
Manicure Set Garden Decorations http://www.chinawholesaletown.com/wholesale-Tellurion/ Umbrella
Lunch Box Wholesale Mouse http://www.chinawholesaletown.com/wholesale-Clothes-Rack/ Wedding Favors
Wine Set Industrial Supplies http://www.chinawholesaletown.com/wholesale-Pen-Holder/ Scarf
Wholesale Sticker Wholesale Stationery http://www.chinawholesaletown.com/wholesale-Waterproof-Case/ Poncho
Wholesale Clothing Wholesale Flag http://www.chinawholesaletown.com/wholesale-Wine-Set/ Ruler
Wholesale Flashlight Wholesale Helmet http://www.chinawholesaletown.com/wholesale-MP3---MP4---MP5-Player/ lable
Wholesale Wallet Writing Instrument http://www.chinawholesaletown.com/ Baby Products Suppliers
Wholesale Lanyard Wholesale Pin http://www.chinawholesaletown.com/ Book Light
Lady Beauty Care Wholesale Earphone http://www.chinawholesaletown.com/wholesale-Silicone/ Earphone
Electroluminescent Wholesale Gift Bags http://www.chinawholesaletown.com/wholesale-Solar-Products/ Fishing Supplies
Wholesale Badge Advertising Material http://www.chinawholesaletown.com/wholesale-Stuffed-Animals/ Vase
Wholesale Speakers Pen Holder http://www.chinawholesaletown.com/wholesale-Racks/ Furniture
Wholesale Coaster Wholesale Magnifier http://www.chinawholesaletown.com/wholesale-Camera/ Mirror
Wholesale Compass Wholesale Whistle http://www.chinawholesaletown.com/ Audio Video Equipment
Poncho Raincoat Wholesale Mp3 http://www.chinawholesaletown.com/wholesale-Glasses/ Mobile Phone
Health Care Products Wholesale Hardware Tools http://www.chinawholesaletown.com/wholesale-Recorder-Pen/ Pin
Wholesale Flag Wholesale Binoculars http://www.chinawholesaletown.com/wholesale-Business-Gift/ China Wholesale
Audio Video Equipment Coca Cola Gifts http://www.chinawholesaletown.com/wholesale-Sport-Items/ Coin Bank
Wholesale Mouse Wholesale Puzzle http://www.chinawholesaletown.com/wholesale-Fan/ Scissors
Wholesale Calendar Wholesale Racks http://www.chinawholesaletown.com/wholesale-Apron/ Jewelry
Wholesale Umbrella Electroluminescent http://www.chinawholesaletown.com/wholesale-Entertainment/ First Aid Kit
Wholesale Whistle Wholesale Scale http://www.chinawholesaletown.com/wholesale-Pen/ Clothes Rack
Wholesale Towel Entertainment Supplies http://www.chinawholesaletown.com/wholesale-Dartboard/ Dartboard
Wholesale Glasses Fishing Supplies http://www.chinawholesaletown.com/wholesale-Binoculars/ USB Flash Drive
Reflective Safety Vest Wholesale Pom Poms http://www.chinawholesaletown.com/wholesale-Ashtray/ Watch
Bottle Opener Wholesale Mobile Phone http://www.chinawholesaletown.com/wholesale-Kitchenware/ Pedometer
Wholesale Banner Wholesale Clap Hands http://www.chinawholesaletown.com/wholesale-Radio/ Calculator
Wholesale Clap Hands Wholesale USB Products http://www.chinawholesaletown.com/wholesale-Cup/ Banner
Garden Decorations Wholesale Speakers http://www.chinawholesaletown.com/wholesale-Bag/ Frisbee
Wholesale Cards Sport Support Products http://www.chinawholesaletown.com/wholesale-Helmet/ Speakers
Wholesale Halloween Gift Men Beauty Care http://www.chinawholesaletown.com/wholesale-Book-Light/ Pen Holder
Wholesale Bracelet Silicone Products http://www.chinawholesaletown.com/wholesale-Medicine-Instrument/ Fan
Christmas Gifts Outdoor Leisure Products http://www.chinawholesaletown.com/wholesale-Money-Bank/ Recorder Pen
Wholesale Scissors Wholesale Lighter http://www.chinawholesaletown.com/wholesale-Jewelry/ Heating Products
Wholesale Candle Wholesale Golf Products http://www.chinawholesaletown.com/wholesale-Clothing/ Stuffed Animals
Wholesale Lighter Wholesale Stress Ball http://www.chinawholesaletown.com/wholesale-Water-Bottle/ Cap
Ok, the use of "haunted" to describe products which get patched, is getting old. It's a software product, not a haunted house.
@PB_z

And "gaping". I'm paranoid about security but these words became hackneyed, as far as Naraine's use, long ago.
0 Votes
+ -
Obviously all browser have had secuity issues
jscott418 Updated - 12th Oct
@PB_z So I read security briefs and all browsers have had zero day holes. I never heard any of these Firefox or Chrome users talking about going to another browser. Exploits come around every month to at least one popular browser. I never cry the sky is falling over any with Firefox or Chrome. Why should anyone with IE?
Ryan Narain's articles are haunted by his lazyness and lack of imagination/creativity.
The last ZDNet article I read was Microsoft panning FireFox and chrome security. Maybe next they will criticize Apple for not being openwith their mobile operating system
@kingcobra23

Oh you mean like all the bugs they patched in the crappy iTunes software? Go look at the list of bugs patched in that POS and then tell me how good Apple is again.
0 Votes
+ -
RE: Internet Explorer 9 haunted by 'critical' security vulnerabilities
LoverockDavidson_-24231404894599612871915491754222 11th Oct
Call in the ghost busters because these hauntings have been exorcised by patching. Really, patches are out, Microsoft Windows will automatically update for you so you don't have to do anything, and the attacker needs to send the user to a specially crafted website which won't be available for 30 days. This isn't much of an issue anymore.
0 Votes
+ -
@LoverockDavidson_

Please read this very carefully:

Microsoft is urging all Windows users to treat this with the utmost priority because of the likelihood of reliable exploit code within 30 days.

Now, please tell me how that can be construed to mean "the attacker needs to send the user to a specially crafted website which won't be available for 30 days "

Go back to school, and take fifth grade over AGAIN!
Interesting that the only adjective this writer knows is "gaping."
0 Votes
+ -
Microsoft Windows & IE......
todbran@... Updated - 11th Oct
Bigger holes than a whorehouse......
@todbran@...

ROFLMAO!

Too bad you got flagged!
THANKS FOR THE REALLY GREAT INFO AOUT IE9, MAKES SENCE AS SOON AS I DOWN LOADED WITHIN 5 MINUTES,USEING IT BOTH LAPTOPS HAD MALIOUSIS VIRUSES,INTURN, 2 PARTITION RESTORE WAS REQUIRED, WHAT A ENORMIOUS P.O.S. THANKS YEP420.
@zzz572

Please stop screaming.
@zzz572 Dude, here is a link you might find helpful: http://www.hookedonphonics.com/
@zzz572

You have NO idea of what "shouting" does to a 'text to speech' program. I could not get the volume down fast enough!!!!
As soon as it was downloaded & used both lap tops crashed with harsh viruses,reqwuireing a 2 partition restore on both comps. What a GIANT P.O.S. THANK YOU ZD.NET!!! You're awesome. Yep420.
@zzz572

Oh no, not harsh viruses!!!!!
One of your sock puppets, @Hallowed are the Ori?

Jeez, you could a least create one that knows how to "spuell"

lol... grin
0 Votes
+ -
Ed Boot where are you???????????
allspammailhere 11th Oct
You should be writing a big post about this, rasing the alarm, and your concerns..... hope we will se at least three posts in a row about this.... happy
...the context of the logged on user. Given IE has Protected Mode the context of the executed code is even less than that of a standard user. Thus severely limiting what the code can do.
0 Votes
+ -
Thanks Ryan
LiquidLearner 11th Oct
Unlike many here I like that you call attention to patches that should be patched ASAP. I don't see why everyone thinks this is to bash Microsoft because it doesn't seem that way to me. More like you're letting people who are responsible for networks know they need to test and deploy these patches. Home PC users should have automatic updates so these are a non-issue for them.
0 Votes
+ -
What ought to happen...
Rodo1 11th Oct
I think we are losing sight of the real problem here. Maybe law enforcement should try to round up the folks writing these exploits and then we hang them. Problem solved.
@Rodo1
And you will find and prosecute these folks....how?
Are you gonna do this by yourself or you will need the help of another 4-year old?
What? Critical security holes in Microsoft software?
Why are people surprised at this? We've seen "critical" holes in microsoft software for decades now. At least now things are better than when they were peddling those disasters called Win 98 and Win ME.
@kraterz

I could think of two Microsoft "products" I would never use:

Microsoft Windows for Aircraft (ad tag line: "Where do you want to crash today?")

Microsoft Windows for Nuclear Reactors (ad tag line: "Where the term 'Global Meltdown' takes on a new meaning.")
The only thing I see wrong here is a lot of ifs. I guess it depends on what if is. Microsoft notified the world that there could be an issue with its software if user don't apply and update, one in which they are providing. What is so gaping about. Move along everybody! There is absolutely nothing worth seeing here!
0 Votes
+ -
Could the two hacks writing this try and sensationalize this anymore?! No issue with the crappy iTunes software and the multiple vulnerbilities patched in that POS.
@hopp64
Browser is THE most important app on your computer. iTunes on a PC sucks, I agree, but it is not a crucial app like a browser.

In my opinion, the best and safest browsing experience is Chrome on a Mac...
@prof123 because Chrome or OS X NEVER require security patches for flaws??????

Or because the market share of both is so small its less of a risk when security flaws on both go unpatched longer than those on Windows????
0 Votes
+ -
Thanks ZDNet
MSFTWorshipper 11th Oct
all the trolls were baited, like flies on ****.
Internet Exploder 9 is the worst browser in the world. I work in an environment where our students have the option to use either IE or Chrome....99% use Chrome because it just works unlike all the incompatibilities IE has with numerous sites.
@Ranpat86@... 99% of those using Chrome get their data raped by Google.
@JeveSobs
And Google are just copying MS who has been doing the same for decades....
0 Votes
+ -
So much for "New and improved"
Willnott 12th Oct
Heh - Deja Vu with just about every commercial product on the market - New and improved usually does not equate to a better customer experience at all - only a better "business picture" for the parent company.
IE with security vulnerabilities? So what else is new?

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix