Microsoft IE browser exposes zero-day vulnerability: an old file can cause system files to be stolen

Publisher:骄阳少年Latest update time:2019-04-14 Source: IT之家 Reading articles on mobile phones Scan QR code
Read articles on your mobile phone anytime, anywhere

According to ZDNet on April 13, security researchers have released details and proof-of-concept code for a zero-day vulnerability in Internet Explorer (IE browser), which allows hackers to steal files from Windows systems.

  The vulnerability can be used to attack when a user opens a .mht file. MHT stands for MHTML Web Archive, which is the default method used by Internet Explorer to save web pages.

  This method is mainly related to IE browsers, because newer browsers no longer save web pages in MHT format, but use HTML format, but they still support processing MHT files.

  On Windows, MHT files are automatically set to open in IE browser by default, and IE is also the default program to open MHT files. It is very easy for hackers to exploit this vulnerability. They only need to distribute MHT files through email, instant messaging, etc.

  Security researcher John Page said the vulnerability could "allow local file disclosure" and allow an attacker to remotely spy on "locally installed program version information." He said the page could also be automated.

  Microsoft released a notice on this issue on March 27, and in a message to researchers on April 10, it said that it was "considering fixing this in future products or services." Microsoft also said that this vulnerability should not be taken lightly, as cybercriminal groups have used MHT files for phishing and malware distribution in the past few years.


Reference address:Microsoft IE browser exposes zero-day vulnerability: an old file can cause system files to be stolen

Previous article:Microsoft confirms hackers had access to some Outlook accounts for months
Next article:How do Amazon and Microsoft address cybersecurity?

Latest Security Electronics Articles
Change More Related Popular Components

EEWorld
subscription
account

EEWorld
service
account

Automotive
development
circle

About Us Customer Service Contact Information Datasheet Sitemap LatestNews


Room 1530, 15th Floor, Building B, No.18 Zhongguancun Street, Haidian District, Beijing, Postal Code: 100190 China Telephone: 008610 8235 0740

Copyright © 2005-2024 EEWORLD.com.cn, Inc. All rights reserved 京ICP证060456号 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号