TioSam Posted September 17, 2012 Report Posted September 17, 2012 A security researcher has found a new 0day vulnerability affecting Internet Explorer, while analyzing a malware page that was being used to exploit vulnerabilities in Java. According to Metasploit team, Internet Explorer 7, 8 and 9 on Windows XP, Vista and 7 are vulnerable to this attack.Eric Romang has discovered a folder "/public/help" in one of the infected hosts. He found a flash file (. Swf), two html pages (protect.html, exploit.html) and exe file.More Info: Zero-Day Season Is Really Not Over YetIf we have to exploit this vulnerability module from Metasploit, you need to update it from the following link: https://community.rapid7.com/docs/DOC-1975The screenshot below shows a successful attack against a machine of Windows 7 with Internet Explorer 9 installed:It is against Internet Explorer 8 installed:Here is another example of exploitation in a Windows XP SP3 box, fully patched:More Info: https://community.rapid7.com/community/metasploit/blog/2012/09/17/lets-start-the-week-with-a-new-internet-explorer-0-day-in-metasploitEnjoy! Quote