SOLVED Another Zero Day Exploit for IE

Trouble

Noob Whisperer
Moderator
Joined
Nov 19, 2013
Messages
13,396
Reaction score
2,318
Again another phishing exploit from files sent to potential victims in emails, messaging apps and other vectors.
Microsoft was notified but declined to patch
Page said he notified Microsoft about this new IE vulnerability on March 27, but the vendor declined to consider the bug for an urgent security fix in a message sent to the researcher yesterday, April 10.
"We determined that a fix for this issue will be considered in a future version of this product or service," Microsoft said, according to Page. "At this time, we will not be providing ongoing updates of the status of the fix for this issue, and we have closed this case."
SOURCE: https://www.zdnet.com/article/internet-explorer-zero-day-lets-hackers-steal-files-from-windows-pcs/
So.... as always, be very careful when opening files sent to you by anyone, even those you would normally trust.
NOTE: The important take away should be that you don't have to use Internet Explorer, it just has to be present on your machine which of course if the case with any Windows OS. Internet Explorer is the default program used to open the malicious .MHT files.
 
Last edited:

Trouble

Noob Whisperer
Moderator
Joined
Nov 19, 2013
Messages
13,396
Reaction score
2,318
Have to wonder.... when MS is gonna cut IE completely out of the Windows OS.
OR
At least give us an option to disassociate it from any default file function(s).

The first thing I did was try to change the default program for opening .MHT files. IE was the only option.
Just an option to "Always ask" would give me some peace of mind.
 
Joined
Sep 26, 2017
Messages
3,641
Reaction score
627
Hmm, seems the .mht format is controlled to the same extent as the .pub/Publisher format, nothing else works. And we won't even talk about .pst/.ost of Outlook.
 

Trouble

Noob Whisperer
Moderator
Joined
Nov 19, 2013
Messages
13,396
Reaction score
2,318
Been hearing some things about a software product called Scribus https://www.scribus.net/
Which according to some reports, the latest version will work with Publisher ( .pub ) files.
IDK, I've never tried it but it might be worth looking into.
 
Joined
Sep 26, 2017
Messages
3,641
Reaction score
627
Looks like I'm going to have to try Scribus. It appears also to be cross-platform with Linux.
 

Trouble

Noob Whisperer
Moderator
Joined
Nov 19, 2013
Messages
13,396
Reaction score
2,318
Great.... let us know.
Often, some elements will not cross over (borders, some fonts, complex shapes, etc.)
So if this Scribus thingy works out, it'd be nice to know.
Just in case I ever decide to drop my 365 subscription.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top