From the group that found it:
Quote:
The vulnerability affects IE6 through IE11, but the attack is targeting IE9 through IE11. This zero-day bypasses both ASLR and DEP. Microsoft has assigned CVE-2014-1776 to the vulnerability and released security advisory to track this issue.
Threat actors are actively using this exploit in an ongoing campaign which we have named “Operation Clandestine Fox.” However, for many reasons, we will not provide campaign details. But we believe this is a significant zero day as the vulnerable versions represent about a quarter of the total browser market. We recommend applying a patch once available.
http://www.fireeye.com/blog/?p=5312
They missed this MSIE vulnerability for over 13 years. It has been in the code since IE 6. Where were all the 100,000+ MS employees who supposedly check their software?
The bad guys may have been using this vulnerability for over three years. The bad guys seem to be more motivated than the good guys. The researchers who discovered it claim that "threat actors" have been using this vulnerability for an unknown period.
Supposedly some 26% of desktop browsers could be affected by this. Better make sure you're getting vendor supported patches (sorry XP users?)!
Linux and OSX are completely unaffected. They don't use MSIE. Chrome was unaffected. Firefox, Safari, Konqueror, and Opera are not affected.
Quote:
The vulnerability affects IE6 through IE11, but the attack is targeting IE9 through IE11. This zero-day bypasses both ASLR and DEP. Microsoft has assigned CVE-2014-1776 to the vulnerability and released security advisory to track this issue.
Threat actors are actively using this exploit in an ongoing campaign which we have named “Operation Clandestine Fox.” However, for many reasons, we will not provide campaign details. But we believe this is a significant zero day as the vulnerable versions represent about a quarter of the total browser market. We recommend applying a patch once available.
http://www.fireeye.com/blog/?p=5312
They missed this MSIE vulnerability for over 13 years. It has been in the code since IE 6. Where were all the 100,000+ MS employees who supposedly check their software?
The bad guys may have been using this vulnerability for over three years. The bad guys seem to be more motivated than the good guys. The researchers who discovered it claim that "threat actors" have been using this vulnerability for an unknown period.
Supposedly some 26% of desktop browsers could be affected by this. Better make sure you're getting vendor supported patches (sorry XP users?)!
Linux and OSX are completely unaffected. They don't use MSIE. Chrome was unaffected. Firefox, Safari, Konqueror, and Opera are not affected.