State-sponsored attackers likely used IE exploit to target Gmail accounts
Microsoft is warning of "active attacks" using a hole in its XML Core Services technology that could allow an attacker to take control of a computer if a user was enticed to open a malicious Web page using Internet Explorer.
Microsoft has a Fix it tool that blocks the attack vector for the vulnerability, but has not issued a security patch yet. Computers running Windows, Office 2003 and Office 2007 are affected.
In its security advisory on the issue, Microsoft acknowledges the Google Security Team for working with the company on the MSXML Uninitialized Memory Corruption Vulnerability. Microsoft … Read more