Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: Currently Unpatched Windows / Internet Explorer Vulnerabilities SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network
https://isc.sans.edu/honeypot.html

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Currently Unpatched Windows / Internet Explorer Vulnerabilities

Thanks to our reader Dan for getting this started. Here is a preliminary table on various Internet Explorer and Windows vulnerabilities that are as of yet unpatched.Let me know if I forgot one. I originally planned to include some of the older issues, but none of them appears to be as relevant/serious as the issues in this list.

CVE Name Release Date Affected Exploit and comments Mitigation
 no CVE Use after free error within "mshtml.dll" Jan 5th 2011 IE 7,8 http://www.vupen.com/english/advisories/2011/0026  
CVE-2010-3970 Graphics Rendering Engine Jan 4th 2011 Windows XP/VIsta (not: 7, 2008 R2) Available

Disable shimgvw.dll

MSFT Advisory #2490606

no CVE WMI ActiveX Control Dec 23rd 2010 IE with WMI ActiveX Control installed
See this Websense blog for details
set killbit on affected ActiveX control
CVE-2010-3971 CSS Import Rule Processing Use-After-Free Vulnerability Dec 14th 2010 IE 6,7,8 PoC available. Critical

Enhanced Mitigation Experience Toolkit

MSFT Advisory #2488013

 

------
Johannes B. Ullrich, Ph.D.
SANS Technology Institute
Twitter

I will be teaching next: Defending Web Applications Security Essentials - SANS San Francisco Winter 2019

Johannes

3676 Posts
ISC Handler
Vuln. in IIS FTP from just before xmas:
http://blogs.technet.com/b/srd/archive/2010/12/22/assessing-an-iis-ftp-7-5-unauthenticated-denial-of-service-vulnerability.aspx
Anonymous
VUPEN has a whole list of unpatched Windows vulnerabilities:

http://www.vupen.com/english/Unpatched-Microsoft-Vulnerabilities.php
Anonymous

Sign Up for Free or Log In to start participating in the conversation!