New MyDoom variants draw on Unpatched IFrame Vulnerability
Tuesday, 09 November 2004 by Michel Roth
A new version of MyDoom uses an unpatched vulnerability in Microsoft's Internet Explorer to spread. As mentioned, the vulnerability has not yet been patched. Windows XP Service Pack 2 is not vulnerable.

Read the about vulnerability here.

An article on CNET.com about this new MyDoom variant can be found here.

Update: also the Bofra worm uses this vulnerability.

Related Items:

Unpatched Internet Explorer Vulnerability, Exploit Released (8 November 2004)
Internet Explorer "object" Tag Memory Corruption Code Execution (26 April 2006)
Here are the extra Microsoft security updates for december 2004 (14 December 2004)
Citrix Metaframe XP Unspecified Buffer Overflow Vulnerability (23 December 2004)
Warning: Microsoft Windows WMF Handling Arbitrary Code Execution - Exploit In the Wild (29 December 2005)
VERITAS Backup Exec Arbitrary File Download Vulnerability, Exploit In the Wild (12 August 2005)
Comments (0)add feed
password
 

busy