New exploit targets Internet Explorer zero-day flaw
If you haven't upgraded to the latest version of Internet Explorer, you may soon be under attack.

An exploit has been published which targets an unpatched flaw in Internet Explorer (IE) 6 and 7.
Security firm Symantec tested the exploit and confirmed that it did work, though it was unreliable. However its analysis team said that they expected a fully-functional exploit to work in the near future.
If this exploit is used, attackers will be able to insert the exploit into websites. If an IE6 or IE7 user does browse one of these sites with Javascript enabled, they will be infected and their computer compromised.
The exploit targets a flaw in the way IE uses cascading style sheets (CSS), which is used to define the presentation of a website's content.
Symantec advised Internet Explorer users to ensure their antivirus was up to date, disable JavaScript and only visit websites they trusted until a fix was available.
IT PRO has contacted Microsoft for comment, but the company had not responded at the time of publication.
There have been no reports of any exploits in the wild, but IT PRO blogger Davey Winder said that this could all change as hackers look to rush out attacks before security vendors have updated signatures to find the exploit.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He said: "Microsoft, will, I imagine, be reactive rather than proactive with a patch only being prioritised after such attacks become widespread."
In August, Microsoft defended its ongoing use of Internet Explorer 6, which still has a quarter of web users, claiming that it was a matter of personal choice.
However, it did admit that as engineers, it wanted to see people upgrading to the latest versions.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
The threat prevention buyer's guide
Whitepaper Find the best advanced and file-based threat protection solution for you
By ITPro Published
-
Supply chain as kill chain
Whitepaper Security in the era Zero Trust
By ITPro Published
-
Microsoft under fire for “negligent” security practices in scathing critique by industry exec
News Microsoft took more than 90 days to issue a partial fix for a critical Azure vulnerability, researchers found
By Ross Kelly Published
-
Apple patches zero day linked to spyware campaign
News Kaspersky researchers were the first to report a zero day used in a sophisticated attack chain
By Rory Bathgate Published
-
MOVEit cyber attack: Cl0p sparks speculation that it’s lost control of hack
News The hackers return with their second major data-extortion attack of 2023, but may have bitten off more than they can chew
By Connor Jones Published
-
Microsoft says it knows who was behind cyber attacks on MOVEit Transfer
Dozens of organizations may have already lost data to hackers exploiting the critical flaw
By Rory Bathgate Published
-
Trend Micro security predictions for 2023
Whitepaper Prioritise cyber security strategies on capabilities rather than costs
By ITPro Published
-
Windows, macOS, and Tesla exploits debuted at Pwn2Own hacking contest
News Researchers took home more than $375,000 in winnings on the first day of the competition
By Ross Kelly Published