ARN

Hackers used IE zero-day, not PDF, in China-Google attacks

McAfee blames unpatched IE bug; Microsoft to release security advisory later today

Hackers exploited an unpatched vulnerability in Microsoft's Internet Explorer (IE) browser to break into some of the firms targeted in a widespread attack that compromised Google's and Adobe's corporate networks last year and earlier this month, McAfee said today.

According to Dmitri Alperovitch, vice president of threat research at McAfee, the unpatched vulnerability in IE was the only exploit used to hack into several of the companies attacked starting last month. Other researchers have said that as many as 33 firms, including Google and Adobe, were attacked, their networks compromised and in some cases, data stolen.

Alperovitch said that Microsoft would release additional information about the IE vulnerability in a security advisory later today.

"Microsoft is investigating these reports and will provide more information when it is available," a Microsoft spokesman said in an e-mail.

Computerworld reported earlier this week that Google and Adobe, the only two companies to have stepped forward thus far to acknowledge the attacks, were hacked using malicious PDF files that exploited a zero-day vulnerability in Adobe's popular Reader software. According to Mikko Hypponen, the chief technology officer of F-Secure, the exploited flaw was the one of eight that Adobe patched Tuesday . That bug had been public knowledge since mid-December, and had been exploited in targeted attacks -- the very kind that broke into Google, Adobe and a reported 32 other major companies -- since sometime in November.

Alperovitch, however, rejected the idea that a rogue PDF was at the root of the attacks. "We have not seen, in all the organizations we've worked with on this, and there were multiple, any PDF files associated with the attack," he said.

Other sources, who asked to remain anonymous because they were not officially allowed to comment, said that Microsoft would release its advisory around 4 p.m. ET.

Come socialise with us! Facebook | LinkedIn

More about: Adobe, F-Secure, Google, McAfee, Microsoft
References show all

Comments

1

roya

Thu 21/01/2010 - 00:21

yoya

tanks for evry think

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: zero day exploit, pdf, mcafee, Google, China, Adobe
ARN Directory | Distributors relevant to this article
Aquion , ASI Solutions , Avnet Technology Solutions , Bluechip Infotech , Compucon Computers , Dicker Data , Express Data , Express Online , Impact Systems Technology , Ingram Micro Australia , Leader Computers , Leading Pacific Australia , MPA Systems , NewLease , Scholastic , Simms International (For Simms International please see Express Online) , Synnex Australia , Topstar Computer International , Westan , Westcon Group , XiT Distribution , Xpress I.T.
rhs_login_lockGet exclusive access to ARN's news, research and invitation only events.
ARN Distributor Directory
ARN Vendor Directory

iAsset is a channel management ecosystem that automates all major aspects of the entire sales,marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.