
Dell Sonicwall Threats Research team has found multiple instances of malicious websites exploiting this old Internet Explorer Vulnerability. This vulnerability is already patched and has been assigned CVE-2012-1889. Metasploit also has a module msxml_get_definition_code_exec and we can see some similarities in the exploit code as outlined below.
There is obfuscation, heap allocation and shellcode setup.
Vulnerable "MSXML3" control is included followed by its function call "definition" that triggers the condition.
Debugging shows heap spray and download of the url containing malicious executable.
A separate variant uses IP address for executable download
We detect multiple variants of this attack by following IPS signatures
Share This Article

An Article By
An Article By
Security News
Security News