« View all Symantec Security Threatcon Articles
Symantec Security Threatcon Status for 2010-02-08
 Microsoft has released a new security advisory to address vulnerabilities affecting Internet Explorer browsers. The advisory has been released in response to a report published by CORE (CORE-2009-0625), which disclosed two remote file-access vulnerabilities affecting the browser. The issues can be exploited by a remote website to obtain file contents or to render script contained in a target file in the Security Zone that is assigned to the target file's source. The vulnerability is trivially exploitable and is likely to be exploited in the wild.
Details for exploitation of these issues is public. Customers are advised to read the following Microsoft Security advisory as soon as possible for workaround information.
Microsoft Security Advisory (980088) Vulnerability in Internet Explorer Could Allow Information Disclosure http://www.microsoft.com/technet/security/advisory/980088.mspx
Microsoft Internet Explorer URLMON Sniffing Cross Domain Information Disclosure Vulnerability http://www.securityfocus.com/bid/38056
|