Clunky-B Trojan Rides IE Flaw
Microsoft had warned last week, that both proof-of-concept code and an exploit are out, to take advantage of an un-patched bug in Internet Explorer.
The security flaw in IE - originally reported in May, was initially thought to allow only a denial-of-service (DOS) attack. However security vendor - Computer Terrorism said that the vulnerability could be exploited to hijack a computer, by simply luring users to a malicious Web site.
Microsoft has not patched the bug as yet; but has said it will either provide a security update through its monthly release, or will offer an out-of-cycle security update.
Meanwhile security major - Sophos has reported evidence of new malware, dubbed the Clunky-B Trojan horse, which exploits the IE bug.
According to Graham Cluley, senior technology consultant, Sophos, the Clunky-B Trojan horse allows hackers to install and run malicious software on users' machines, when they visit sites containing the malware.