Уровень 0 · материалов: 4
В кластер включаются документы об уязвимостях нулевого дня в браузерах на ОС Windows, приводящих к выполнению кода или краже данных, и исключаются сообщения о простых сбоях верстки или коде для вызова краша браузера.
Общие признаки: zero-day уязвимости, удаленное выполнение кода, Internet Explorer, сбои в работе системы, Windows
Группа выше: Уязвимости конкретных продуктов и платформ
Смысл: The main idea is to report on a sophisticated zero-day exploit in IE9 that allows arbitrary code execution by bypassing advanced Windows 7 security features, emphasizing the vulnerability of the mshtml.dll library.
Cybersecurity firm Vupen discovered a zero-day exploit in IE9 that bypasses Windows 7's DEP, ASLR, and sandboxing via a use-after-free error in mshtml.dll.
Смысл: The text warns about an active zero-day exploit in Internet Explorer (versions 7-9) that allows attackers to take control of a user's system through malicious websites, urging users to switch browsers until Microsoft provides a patch.
A critical zero-day vulnerability in Internet Explorer versions 7-9 allows remote system compromise, leading experts to advise against using the browser until a patch is released.
Смысл: The text informs users about a zero-day vulnerability in all Windows versions involving the Internet Explorer MHTML handler, which allows attackers to execute malicious scripts to steal data, and notes that the only immediate solution was to avoid opening such files.
A zero-day vulnerability in Windows' MHTML handler in Internet Explorer allows attackers to steal information via malicious files, with no patch available at the time of reporting.
Смысл: The text informs about a zero-day vulnerability in Windows 7 x64 where a malicious website viewed in Safari can crash the system (BSOD) and allow kernel-level remote code execution via a flaw in win32k.sys.
A critical kernel-level vulnerability in Windows 7 x64 allows remote code execution via Safari browsing, with no patch available at the time of reporting.