Blimey, I've been loceked-up in a network room for 2 weeks, but I just found out about this new DoS proof-of-concept that was released last week...
http://isc.sans.org/diary.php?storyid=1198
Quote:
|
Originally Posted by Sans
There is a new and unpatched vulnerability with exploit code in the wild that affects the latest version of IE. The exploit works by including an abnormally large (a couple thousand) number of script actions inside a single HTML tag. This will cause a memory array to write out of bounds and cause an immediate or eventual browser crash.
|
AV signatures are already available, but imho this is yet another reason to make the switch