Back to Forums








View Full Version : Zero-Day Hits IE-Firefox Combo


Reverend
July 10th, 2007, 21:00 PM
Security researcher Thor Larholm has discovered a zero-day vulnerability that could lead to remote attackers hijacking systems running both Internet Explorer and Firefox.

Larholm is calling this an IE zero day, blaming the vulnerability on an input validation flaw in Internet Explorer that allows users to specify arbitrary arguments to the process responsible for handling URL protocols. It's t...

More... (http://www.techzonez.com/comments.php?shownews=21633)

egghead
July 11th, 2007, 02:21 AM
The flaw arises when IE fails to validate the handler and passes any parameters in the request directly to the firefox.exe process as arguments or options.

lovely

blackhat
July 11th, 2007, 18:18 PM
Since my current setup has run w/o problem for over 4 yrs, I haven't learned much about computer architecture since the days when Dos and Windows were separable and I had the "Hood up" regularly.
Can these types of vulnerabilities be exploited when:
1) Browser open, logged on w/administrator privileges.
2) Browser open, logged on w/o admin. privileges.
3) Browser closed, logged on as administrator.
4) Browser closed, logged on w/o administrator privileges.
I guess my question is, How can someone get remote access to operate on my Browser? DRB