Microsoft issues temporary fix for zero-day IE vulnerability

Microsoft has released a workaround for a zero-day vulnerability affecting versions 6, 7 and 8 of Internet Explorer.

The flaw became known when it was used as part of a so-called "watering hole" attack against the website for the policy think tank Council on Foreign Relations, the influential membership group that helps shape U.S. foreign policy.

About two weeks ago, the site was hijacked with malicious JavaScript to serve an Adobe Flash exploit, which in turn triggered a heap-spray attack, according to researchers at security firm FireEye. The malware was delivered to users whose operating system language was set to English, Chinese, Japanese, Korean or Russian.

Microsoft on Saturday acknowledged in an advisory that the vulnerability has been used in a limited number of targeted attacks. At least one other organization, Chatsworth, Calif.-based microturbine systems supplier Capstone Turbine Corp., had its website compromised to take advantage of the bug, security researcher Eric Romang said Wednesday in a blog post.

On Monday, Microsoft released a Fix-It tool, which, if applied, "prevents the vulnerability from being used for code execution without affecting your ability to browse the web," Dustin Childs, group manager of response communications for Microsoft Trustworthy Computing, wrote in a blog post. Users also can upgrade to IE 9 or 10, which are not affected by the issue.

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.