Quantcast

New Generation of IE Malware Now Circulating

Exploit is based on earler flaw but considered more dangerous.

Robert McMillan, IDG News Service

  • 0 Yes
  • 0 No

SAN FRANCISCO -- Hackers have posted a new version of malicious software that will make it easier for them to exploit an unpatched vulnerability in Microsoft's Internet Explorer browser. Based on a critical bug disclosed on March 22, the software was posted by hackers today to the Milw0rm.com Web site.

The code exploits a flaw in the way IE processes Web pages using the createTextRange() method. Hackers have been using malware that takes advantage of this vulnerability to install unauthorized software on victims' computers over the past week, but this new generation is considered to be more dangerous, according to security researchers.

How It Works

Older versions of the malware could freeze victims' browsers for more than a minute, giving them an opportunity to shut down their computers or stop the malicious software before it could complete its work. But the new software works more quickly, meaning it will be particularly effective on older machines with limited memory and processing capabilities, says Craig Schmugar, researcher with McAfee Avert Labs.

Though hackers had not widely adopted the new software as of Friday morning, Schmugar says he expects that to change. "It's still pretty early," he notes. "I think it's reasonable to expect that people will shift."

The software also uses new techniques to avoid certain types of signatures used by antivirus vendors, says Aviv Raff, a security researcher based in Israel. "It's much more effective," he warns. "I think people should know and understand that ... now they are more vulnerable."

That the code was released just before the weekend is also worrisome, because it means that "administrators have to wait for Monday to apply their protections and to give warning to users," says Juha-Matti Laurio, a security researcher in Helsinki.

Official Fix Not Expected Until April 11

With a fix for the problem expected as late as April 11--the date of Microsoft's next scheduled security update--security companies Determina and eEye Digital Security have issued unsupported patches for the problem. According to eEye, there have been more than 70,000 downloads of its software since its Monday release.

Microsoft does not recommend that users install these patches. Instead, it recommends that disabling IE's Active Scripting feature as a workaround.

Despite the severity of the TextRange() bug, McAfee says that the malware that takes advantage of it is not particularly widespread. This software at present ranks number 13 in McAfee's list of the top 20 pieces of malware being reported, Schmugar says.

  • Recommend this story?
  • 0 Yes
    0 No

"New Generation of IE Malware Now Circulating" Comments

Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.

Featured APC Accessories For Your System
10% Off Entire Cart at Online Store

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

  • 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
  • Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.

PC World's Marketplace