The Symantec folks identified a website exploiting a bug from this months Microsoft patches, specifically the Microsoft Internet Explorer Speech API 4 COM Object Instantiation Buffer Overflow Vulnerability. Here is the URL to their blog entry:
http://www.symantec.com/enterprise/security_response/weblog/2007/06/deepsight_honeynet_detects_obf.html
Apparently, the actual exploit is similar to the proof of concept code posted on a popular exploit site ten days ago.
Login here to post a comment. Diary Archive