Finally stopped using Internet Explorer?Watch The Tax Collector Online Good! But, now it’s time to completely delete it from your computer, too.
Security researcher John Page has discovereda new security flawthat allows hackers to steal Windows users’ data thanks to Internet Explorer. The craziest part: Windows users don’t ever even have to open the now-obsolete web browser for malicious actors to use the exploit. It just needs to exist on their computer.
“Internet Explorer is vulnerable to XML External Entity attack if a user opens a specially crafted .MHT file locally,” writesPage. “This can allow remote attackers to potentially exfiltrate Local files and conduct remote reconnaissance on locally installed Program version information.”
Basically, what this means is that hackers are taking advantage of a vulnerability using .MHT files, which is the file format used by Internet Explorer for its web archives. Current web browsers do not use the .MHT format, so when a PC user attempts to access this file Windows opens IE by default.
To initiate the exploit, a user simply needs to open an attachment received by email, messenger, or other file transfer service.
“[For] example, a request for "c:\Python27\NEWS.txt" can return version information for that program,” Page explains. “Upon opening the malicious '.MHT' file locally it should launch Internet Explorer. Afterwards, user interactions like duplicate tab 'Ctrl+K' and other interactions like right click 'Print Preview' or 'Print' commands on the web-page may also trigger the XXE vulnerability.”
The exploit has been tested using the last version of Internet Explorer, IE 11. It affects Windows 7, Windows 10, and Windows Server 2012 R2 users.
Most worrisome, according to Page, is that Microsoft told him that it would just “consider” a fix in a future update. The security researcher says he contacted Microsoft in March before now going public with the issue.
As ZDNetpoints out, while Internet Explorer usage makes upless than 10 percent of the web browser market, it doesn’t particularly matter in this case as the exploit just requires a user to have the browser on their PC.
Earlier in 2019, Microsoft cybersecurity expert Chris Jackson urged anyone still using Internet Explorer to finally give it up. The company officially discontinued its former flagship web browser in 2015.
Topics Cybersecurity Microsoft Windows
ChatGPT has gone down the day after ChristmasNYT Strands hints, answers for December 24Manchester City vs. Everton 2024 livestream: Watch Premier League for freeFalcons vs. Commanders 2024 livestream: How to watch NFL onlineWordle today: The answer and hints for December 26Manchester City vs. Everton 2024 livestream: Watch Premier League for freeWordle today: The answer and hints for December 28Wordle today: The answer and hints for December 28NYT Connections Sports Edition hints and answers for December 27: Tips to solve Connections #95NYT Connections hints and answers for December 25: Tips to solve 'Connections' #563.Titans vs. Jaguars 2024 livestream: How to watch NFL onlinePanthers vs. Buccaneers 2024 livestream: How to watch NFL onlineSteven Moffat and Russell T Davies on 'Doctor Who's Christmas special's endingNASA spacecraft just plunged into the sun and broke stunning recordsWordle today: The answer and hints for December 29James Bond is canon in 'Doctor Who' nowTitans vs. Jaguars 2024 livestream: How to watch NFL onlineNYT mini crossword answers for December 28NYT Connections hints and answers for December 26: Tips to solve 'Connections' #564.Hackers take over Google Chrome extensions in cyberattack 11 best sex and relationship podcasts of 2023 Welcome to Season 2 of The Paris Review Podcast by The Paris Review Emeric Pressburger’s Lost Nazi Novel by Lucy Scholes Staff Picks: Biopics, Blades, and Balloons by The Paris Review How to watch FAMU vs. Howard football livestreams: kickoff time, streaming deals, and more Best online courses for AI, ChatGPT, Midjourney, and more All the best mattress deals of Cyber Monday 2023 A Change in the Climate by Michel Faber 'American Fiction' review: A great setup with no punchline NYT's The Mini crossword answers for December 15 Porn viewers skyrocket during work hours, study finds Best iPad deal: Get the 2021 iPad Mini (6th gen) for $539.99 On Line: The Pulse of Agnes Martin by John Vincler Why is everyone obsessed with Snoopy now? Nick Tosches in a Trench Coat by Brian Cullman How to watch Cal vs. Texas Tech football livestreams: kickoff time, streaming deals, and more 9 Cyber Monday air fryer deals: Instant Pot Vortex, more Holy moly, shoppers spent so much money this Black Friday How to watch ODU vs. WKU football livestreams: kickoff time, streaming deals, and more The Many Reincarnations of Kim Deitch by Bill Kartalopoulos
2.1828s , 10127.71875 kb
Copyright © 2025 Powered by 【Watch The Tax Collector Online】,Miracle Information Network