New Exploit Targets Older Versions of Internet Explorer

Symantec is reporting that older versions of Microsoft Internet Explorer are susceptible to a new attack against a vulnerability in its cascading style sheets (CSS). While a working exploit hasn’t been detected, Symantec suspects that it’s only a matter of time before hackers start actively using this new vulnerability with a full-functioning exploit.   According […]

Written By: Lawrence Walsh
Nov 23, 2009
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Symantec is reporting that older versions of Microsoft Internet Explorer are susceptible to a new attack against a vulnerability in its cascading style sheets (CSS). While a working exploit hasn’t been detected, Symantec suspects that it’s only a matter of time before hackers start actively using this new vulnerability with a full-functioning exploit.
 
According to Symantec, the CSS vulnerability affects versions 6 and 7 of the Microsoft browser. Exploits currently detected are unreliable, meaning that they don’t always work. However, when a working, full-functioning exploit is produced, Symantec says hackers will be able to inject malicious code into Web sites and stealthily infect PCs.

Symantec says malicious code attacking the vulnerability are detected with the current Bloodhound.Exploit.129 antivirus signature, as well as the HTTP Microsoft IE Generic Heap Spray BO and HTTP Malicious Javascript Heap Spray BO IPS signatures. Since these signatures aren’t fully reliable, Symantec is working on a new set of signatures specifically for this vulnerability.

Until Microsoft releases a patch for the CSS vulnerability, Symantec advises PC users to update antivirus signatures, disable JavaScript and only visit trustworthy Web sites.

Recommended for you...

Arctic Wolf Research: Cyber Insurance Driving Security Needs

Arctic Wolf’s 2025 outlook shows MSP opportunities as insurers tackle ransomware threats and emerging AI risks through expanded security partnerships.

Victoria Durgin
Aug 14, 2025
Brivo Launching New Solution to Boost Security Suite

Brivo and Envoy partner to unify access control & visitor management, delivering scalable, compliant, and secure workplace experiences.

Jordan Smith
Aug 13, 2025
MetTel to Modernize Communication Lines for VA

MetTel secures a $54M contract to modernize 15,000 VA phone lines across 1,875 locations using its POTS Transformation solution, enhancing reliability and performance.

Jordan Smith
Aug 8, 2025
Galactic Advisors Wins Credential-Free Assessment Patent

Galactic Advisors patents a user-activated, credential-free pen testing tool, boosting MSP security with risk-free, forensic-grade assessments.

Jordan Smith
Aug 6, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.