Microsoft's Internet Explorer Vulnerabilities Raise Concerns After Recent Hack

Microsoft Corp's Web browser, Internet Explorer, faces new security concerns following the discovery of a set of vulnerabilities by security research firm Core Security Technologies. This latest issue comes on the heels of a high-profile cyber attack on Google and other companies operating in China. Research firm Core Security Technologies found that hackers can exploit a combination of four or five minor vulnerabilities in Internet Explorer, allowing them to remotely access all data on a personal computer. The vulnerabilities, although not serious enough to compromise a machine individually, can be linked together to take control of a PC.

Key Takeaways:

  • Core Security Technologies discovered a set of vulnerabilities in Internet Explorer that hackers can link together to remotely access all data on a personal computer.
  • There are four to five minor vulnerabilities in Internet Explorer that, when combined, can be exploited by hackers.
  • Microsoft has not yet patched these vulnerabilities, leaving users exposed to potential attacks.
  • Internet Explorer is used on hundreds of millions of PCs worldwide, making it a prime target for hackers.
  • A hacker can exploit these vulnerabilities by getting a user to click on a malicious link, giving them access to all data on the PC.
  • Research firm Core Security Technologies will demonstrate the vulnerability at the Black Hat security conference in Washington on February 2.
  • Jorge Luis Alvarez Medina, a security consultant with Boston-based Core, stated that hackers can conduct this type of attack in three or four ways.

Statistics:

  • Hundred of millions: The number of PCs worldwide that use Internet Explorer.
  • 4-5: The number of minor vulnerabilities in Internet Explorer that, when combined, can be exploited by hackers.
  • 1: The number of way a hacker can take control of a PC by exploiting all vulnerabilities at once.
  • 1: The number of user click required for a hacker to gain access to all data on a PC.
  • February 2: Date of the Black Hat security conference in Washington where the vulnerability will be demonstrated.

Sources:

  • Reuters
  • Core Security Technologies
  • Muscat Press and Publishing House SAOC 2009
  • Microsoft Corp