Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
ASUS GeForce RTX 4080 Noctua OC Edition review
MSI Clutch GM51 Wireless mouse review
ASUS ROG STRIX B760-F Gaming WIFI review
Asus ROG Harpe Ace Aim Lab Edition mouse review
SteelSeries Arctis Nova Pro Headset review
Ryzen 7800X3D preview - 7950X3D One CCD Disabled
MSI VIGOR GK71 SONIC Blue keyboard review
AMD Ryzen 9 7950X3D processor review
FSP Hydro G Pro 1000W (ATX 3.0, 1000W PSU) review
Addlink S90 Lite 2TB NVMe SSD review

New Downloads
Intel ARC graphics Driver Download Version: 31.0.101.4148
GeForce 531.29 WHQL driver download
CrystalDiskInfo 9.0.0 Beta3 Download
AMD Ryzen Master Utility Download 2.10.2.2367
AMD Radeon Software Adrenalin 23.3.1 WHQL download
Display Driver Uninstaller Download version 18.0.6.1
CPU-Z download v2.05
AMD Chipset Drivers Download 5.02.19.2221
GeForce 531.18 WHQL driver download
ReShade download v5.7.0


New Forum Topics
Studio Driver 531.41 out now Red Bull and Memento Exclusives bring the racetrack to your home with F1 sims based on RB18 (for 91K USD) Review: ASUS GeForce RTX 4080 Noctua OC Edition Adrenalin 23.3.1 - Clean Driver Version for Ryzen 7000 Series with Integrated GPU Nvidia shows signs ... AMD Software: Adrenalin Edition 23.3.1 WHQL - Driver Download and Discussion Fake Samsung 980 Pro SSDs on the Rise: Beware of Counterfeit Drives Kingston Technology has released their latest DDR5 ECC Registered DIMM lineup up-to 6000 MHz Failed 8,3 Years old WD Red drive 3TB (EFRX) - what now...? Intel’s Raptor Lake Refresh Desktop CPUs Expected to Arrive in August 2023




Guru3D.com » News » New Exploit Targets IE7 Bug

New Exploit Targets IE7 Bug

by Hilbert Hagedoorn on: 02/19/2009 12:05 PM | source: | 0 comment(s)

We can;t say this enough, keep pathing up. It's a vicious cyberworld out there.

Cybercriminals are actively exploiting a critical vulnerability in Internet Explorer 7, which arises from the browser's improper handling of errors when attempting to access deleted objects. This vulnerability allows remote attackers to execute arbitrary codes on a vulnerable machine. The threat starts with a spammed malicious .DOC file detected as XML_DLOADR.A. This file has a very limited distribution script, suggesting it may be a targeted attack. It contains an ActiveX object that automatically accesses a site rigged with a malicious HTML detected by the Trend Micro Smart Protection Network as HTML_DLOADER.AS. HTML_DLOADER.AS exploits the CVE-2009-0075 vulnerability, which is already addressed by the MS09-002 security patch released last week. On an unpatched system though, successful exploitation by HTML_DLOADER.AS downloads a backdoor detected as BKDR_AGENT.XZMS. This backdoor further installs a .DLL file that has information stealing capabilities. It sends its stolen information to another URL via port 443.

If you are current on your patches, you are fine. If not...well, you know the drill.

Analysis by Trend Micro researchers reveal that BKDR_AGENT.XZMS takes screenshots of the infected system and sends these screenshots to a remote malicious location. It also creates a hidden Internet Explorer window which connects to a website to listen for commands.







« Best Selling PC Games · New Exploit Targets IE7 Bug · Intel goes after the money, sues NVIDIA »


Guru3D.com © 2023