Quote Originally Posted by t34b4g5 View Post
Nice heads up.

interesting that it doesn't effect Vista users.
I'm curious as to where you've seen mention of it not affecting Vista users?

From the Microsoft advisory: "Our investigation so far has shown that these attacks are against Windows Internet Explorer 7 on supported editions of Windows XP Service Pack 2, Windows XP Service Pack 3, Windows Server 2003 Service Pack 1, Windows Server 2003 Service Pack 2, Windows Vista, Windows Vista Service Pack 1, and Windows Server 2008."

The example exploit that SANS ISC discussed doesn't target Vista, most likely due to the limited attack surface of IE 7 in Protected Mode on Vista. It would be entirely possible, however, to target Vista with the vulnerability.

That being said... if you've got another article I'm unaware of.. I'd love to read it.

Side note, anyone wanting to look at the code (since it's been sanitized on the SANS ISC site) send me a PM.