{"id":199924,"date":"2021-03-11T23:41:43","date_gmt":"2021-03-11T20:41:43","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/microsoft-patches-internet-explorer-memory-corruption-vulnerability\/"},"modified":"2021-03-11T23:41:43","modified_gmt":"2021-03-11T20:41:43","slug":"microsoft-patches-internet-explorer-memory-corruption-vulnerability","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/microsoft-patches-internet-explorer-memory-corruption-vulnerability\/","title":{"rendered":"#Microsoft patches Internet Explorer memory corruption vulnerability"},"content":{"rendered":"<p>&#8220;<strong>#Microsoft patches Internet Explorer memory corruption vulnerability<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2019\/hacker.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2019\/hacker.jpg\" data-sub-html=\"Credit: CC0 Public Domain\">\n<figure class=\"article-img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800a\/2019\/hacker.jpg\" alt=\"hacker\" title=\"Credit: CC0 Public Domain\" width=\"800\" height=\"530\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                Credit: CC0 Public Domain<br \/>\n            <\/figcaption><\/figure>\n<\/div>\n<\/div>\n<p>On March 9, 2021, Microsoft patched a zero-day security vulnerability related to memory corruption in its browser, Internet Explorer.<\/p>\n<p>                                                                                Labeled CVE-2021-26411, this vulnerability allowed an attacker to deceive a user into visiting a uniquely crafted, malicious website hosted on Internet Explorer. Additionally, an attacker could compromise existing websites by posting malicious advertisements on webpages allowing user-hosted content. While the attacker would first have to use email or instant message to convince the user to engage with these advertisements and websites in order to compromise the victim, malicious actors from across potentially the entire Internet could take advantage of this exploit.<\/p>\n<p>Because the vulnerability existed on the network stack, this CVE qualified as remotely executable. Moreover, the attacker did not require any special escalated privileges to exploit the vulnerability. Once an attack proved successful, an attacker could potentially modify any accessed files and other user information, thus placing the user&#8217;s content integrity at significant risk. <\/p>\n<p>Perhaps most interestingly, the hackers in this case spent weeks building trust specifically with security researches as their target. Since discovery, researchers have traced the attack back to North Korea. The attackers developed a working connection by contacting researchers via an original research blog and created Twitter personas to request collaboration on a project. The fake <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">social media<\/a> profiles would then prompt the researchers to visit a webpage. From there, even a fully patched Windows 10 machine would end up installing a malicious service and in-memory backdoor to communicate with an attacker-controlled server.<\/p>\n<p>Google has attributed the attack to the North Korean government, specifically a threat group called Zinc, linked to the better-known Lazarus. Related to the devastating 2017 ransomware campaign WannaCry, Lazarus has allegedly ranked in $2 billion for North Korea&#8217;s weapons of mass destruction program. <\/p>\n<p>In addition to Internet Explorer, this vulnerability also impacted Edge, Microsoft&#8217;s more secure browser. Furthermore, researchers eventually found that the attackers supplemented their watering-hole attack using malicious websites with a fraudulent Visual Studio Project evidently containing source code for a proof-of-concept exploit. This alleged project actually housed custom malware that contacted the hackers&#8217; control server.<\/p>\n<p>As of now, the vendor has released an official fix and upgrade for this vulnerability. Those Microsoft users who desire immediate updates can visit Start &gt; Settings &gt; Updates &amp; Security &gt; Windows Update on their system.\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            Bug bounty company PingSafe AI discovers iPhone call recording <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a> vulnerability\n                                        <\/p><\/div>\n<hr class=\"mb-4\"\/>\n<div class=\"article-main__more p-4\">\n                                                                                                <strong>More information:<\/strong><br \/>\n                                                &#8220;Internet Explorer Memory Corruption Vulnerability.&#8221; Security Update Guide \u2013 Microsoft Security Response Center, Microsoft, 9 Mar. 2021, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-26411\">msrc.microsoft.com\/update-guid \u2026 ility\/CVE-2021-26411<\/a><br \/>\nGoodin, D. &#8220;Critical 0-Day That Targeted Security Researchers Gets a Patch from Microsoft.&#8221; Ars Technica, Ars Technica, 9 Mar. 2021, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/gadgets\/2021\/03\/microsoft-patches-critical-0day-that-north-korea-used-to-target-researchers\/\">arstechnica.com\/gadgets\/2021\/0 \u2026 -target-researchers\/<\/a><\/p>\n<\/div>\n<p class=\"article-main__note mt-4\">\n                                                \u00a9 2021 <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/sciencee\/\" data-internallinksmanager029f6b8e52c=\"5\" title=\"Science\" target=\"_blank\" rel=\"noopener\">Science<\/a> X Network<\/p>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 Microsoft patches Internet Explorer memory corruption vulnerability (2021, March 11)<br \/>\n                                                 retrieved 11 March 2021<br \/>\n                                                 from https:\/\/techxplore.com\/<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>\/2021-03-microsoft-patches-internet-explorer-memory.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2021-03-microsoft-patches-internet-explorer-memory.html\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Microsoft patches Internet Explorer memory corruption vulnerability&#8221; Credit: CC0 Public Domain On March 9, 2021, Microsoft patched a zero-day security vulnerability related to memory corruption in its browser, Internet Explorer. Labeled CVE-2021-26411, this vulnerability allowed an attacker to deceive a user into visiting a uniquely crafted, malicious website hosted on Internet Explorer. Additionally, an attacker&#8230;<\/p>\n","protected":false},"author":1,"featured_media":199925,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2019\/hacker.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-199924","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/199924","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=199924"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/199924\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/199925"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=199924"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=199924"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=199924"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}