Microsoft discloses zero day in all versions of Internet Explorer

By  for Zero Day |

Late Saturday Microsoft revealed a vulnerability in all versions of Internet Explorer that is being used in “limited, targeted attacks.” They are investigating the vulnerability and exploit and have not yet determined what action they will take in response or when.

All versions of Internet Explorer from 6 through 11 are listed as vulnerable as well as all supported versions of Windows other than Server Core. Windows Server versions on which IE is run in the default Enhanced Security Configuration are not vulnerable unless an affected site is placed in the Internet Explorer Trusted sites zone.

The vulnerability was reported to Microsoft by research firm FireEye. FireEye says that, while the vulnerability affects all versions of IE, the attack is specific to versions 9, 10 and 11. It is a “use after free” attack in which memory objects in the browser are manipulated after being released. The attack bypasses both DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization).

The specific exploit, according to FireEye, uses an Adobe Flash SWF file to manipulate the heap with a technique called heap feng shui. Neither Microsoft nor FireEye says it, but this implies that systems without Flash installed are not vulnerable to the specific exploit, although they are to the underlyng vulnerability in Internet Explorer. Internet Explorer 10 and 11 come with Flash embedded, so they are vulnerable by default.

EMET, the Enhanced Mitigation Experience Toolkit, will also make it more difficult to exploit this vulnerability.

Coming soon: a whole new you, in your Twitter profile

Moment by moment, your Twitter profile shows the world who you are. Starting today, it will be even easier (and, we think, more fun) to express yourself through a new and improved web profile.

What’s new about the new you? The new web profile lets you use a larger profile photo, customize your header, show off your best Tweets and more. Here are main features:

  • Best Tweets: Tweets that have received more engagement will appear slightly larger, so your best content is easy to find.
  • Pinned Tweet: Pin one of your Tweets to the top of your page, so it’s easy for your followers to see what you’re all about.
  • Filtered Tweets: Now you can choose which timeline to view when checking out other profiles. Select from these options: Tweets, Tweets with photos/videos, or Tweets and replies.

Coming soon to everyone
This new profile setup is available today to a small group of users. If you’re new to Twitter, you’ll start in with the new profile. In the coming weeks, we will roll out the new features to everyone.

In the meantime, for a peek at what’s coming, check out these web profiles: