Bitdefender
Resource Center

BITDEFENDER RESOURCE CENTER

March 2010

BitDefender® Protects Users against Zero Day Flaw in Internet Explorer® 6 and 7

Emergency update to protect computer users against malicious remote code execution in Internet Explorer® versions 6 and 7

BitDefender® has released an emergency update to protect computer users against the newly-discovered flaw in Internet Explorer® versions 6 and 7 which could allow remote code execution, after tricking the user into visiting a malicious web page. Microsoft has issued a warning bulletin and a patch is underway to mitigate the vulnerability.


In order to stay safe, BitDefender recommends that you download, install and update a complete antimalware suite with antivirus, antispam, antiphishing and firewall protection and take extra caution when prompted to open files from unfamiliar locations.


Potential Risk Scenario


Initially, a prospective victim is lured into visiting a specially crafted web link advertised either via spam messages or as posted on bulletin boards, social networks etc. This webpage contains JavaScript code obfuscated by using the escape function. In order to bypass detection from antivirus products, the script calls a secondary JavaScript that replaces a variable with the unescape string.


The decrypted result is actually the malicious payload which will trigger a heap spray attack and will write the malicious code into the browser’s User Data area, making it persistent. Every time the browser starts, the malicious code is executed without any subsequent intervention (drive-by download), which will result in the automatic download of a file called either notes.exe or svohost.exe (detected by BitDefender as Gen:Trojan.Heur.PT.cqW@aeUw@pbb).


This approach is similar to the one described in CVE-2010-0249 that has been used in targeted attacks against 34 major corporations including Google™ and Adobe™.


Mitigating the Risks


Microsoft has announced that the exploit is already in the wild and that users will be provided with a fix ‘as soon as possible.’ Since Internet Explorer® 8 is not vulnerable to the attack, the next logical step would be to upgrade immediately. However, many custom-made applications in the corporate environment are strongly interconnected with IE 6 or IE 7 and might not work as expected on Internet Explorer 8.


BitDefender is currently detecting the exploit and blocking the malicious code before it is able to inflict any damage to a user’s computer. Moreover, all BitDefender customers have been proactively protected against the infected binaries which the exploit is trying to install on the local machine.


* * *

About Bitdefender®
Bitdefender is the creator of one of the world's fastest and most effective lines of internationally certified internet security software.Since 2001, the company has been an industry pioneer, introducing and developing award-winning protection. Today, Bitdefender technology secures the digital experience of around 400 million home and corporate users across the globe.

Recently, the company has won a range of key independent recommendations in the US, UK and across Europe, including ConsumerSearch, Which?, Stiftung Warentest and Taenk. Bitdefender antivirus technology has also finished top in leading industry tests from both AV Test and AV-Comparatives. More information about Bitdefender's antivirus products is available from the company's security solutions press room. Additionally, Bitdefender publishes Malware City providing the latest updates on security threats and helping users stay informed in the everyday battle against malware.


Bitdefender's Security News & Alerts
Stay safe online. Click here if you want to receive the latest news and alerts on computer threats, viruses and scams.