24 Dec 2011

Critical Zero-Day Vulnerability In Windows 7 (Exploitable Via Apple's Safari Browser)


Highly critical Zero-day vulnerability found in Windows 7. This security flaws can be exploited via Apple Safari browser.  This was first made public via a twitter user named w3bd3vil 

"<iframe height='18082563'></iframe> causes a BSoD [blue screen of death] on win 7 x64 via Safari. Lol!"


It is reported that vulnerability affects fully patched Windows 7 Professional 64-bit and cautioned that other versions may be affected. The remotely exploitable vulnerability, caused by an error in win32k.sys, enables a hacker to run arbitrary code -- such as malware -- on a victim's machine when he or she visits a specially crafted Web page using Safari. Specifically, the Web page would simply need to contain an iFrame -- an HTML element that is typically used to pull content from other sources onto a Web page -- with an overly large "height" attribute.