Internet Explorer 9 or 10 are
not affected by this vulnerability and upgrading to these versions of IE
is a good option for individual users. IT admins that cannot up[garde
that fast, should take a look at the EMET
toolkit which Microsoft has been listing as a defensive workarounds for
this attack and as well as the last IE 0-day in September (2757760).
Microsoft's SRD blog
post goes over the technical details of the current attacks and
provides some insight how the attackers circumvent IE's built-in
protection mechanisms by using a components from Flash, Java and Office.
Bron: Laws of Vulnerabilities
Geen opmerkingen:
Een reactie posten