Zero-Day Internet Explorer Exploit
Tuesday November 22, 2005
In the strictest sense of the word, this is not a "zero-day" exploit because there have, in fact, been many, many days that have passed by since the original vulnerability was discovered. However, the original vulnerability was only deemed to be a DoS (denial-of-service) risk and was given a low priority by Microsoft so no patch has yet been created for it. Now, exploit code has been released on the Internet which allows for an attacker to gain complete control of the target system, rather than "just a DoS." For more details, you can read this eWeek article or this Microsoft Security Advisory.
