Chat directly with me if you want. Go to my Chat page to find a web messenger!
I guess you might have seen it by now but if not, please make sure you read and understand the material available:
This night we released a Security Advisory on a Vulnerability in Internet Explorer Could Allow Remote Code Execution. The reason for that is that our investigations have shown that this vulnerability was one of the attack vectors used in the recent attacks against Google. So, please read the blog post of our Microsoft Security Response Center on the release of the advisory.
I just want to quote some of the key elements in there:
Based upon our investigations, we have determined that Internet Explorer was one of the vectors used in targeted and sophisticated attacks against Google and possibly other corporate networks.
[…]
Our teams are currently working to develop an update and we will take appropriate action to protect customers when the update has met the quality bar for broad distribution. That may include releasing the update out of band.
Customers should also enable Data Execution Prevention (DEP) which helps mitigate online attacks. DEP is enabled by default in IE 8 but must be manually enabled in prior versions.
There are some additional mitigations shown in the advisory. However, a few things from my side:
I realized that it might be necessary to give an introduction in how to switch DEP on and I therefore wrote a post on that as well today: Leveraging Data Execution Prevention (DEP)
Roger
Posts are so informative where we get lots of information on any topic. Nice job keep it up..
Nice post mate. Very useful one