After analyzing the leaked data from last week’s attack on Hacking Team, Vectra researchers discovered a previously unknown high severity vulnerability in Internet Explorer 11, which impacts a fully patched IE 11 web browser on both Windows 7 and Windows 8.1.
The vulnerability is an exploitable use-after-free (UAF) vulnerability that occurs within a custom heap in JSCRIPT9. Since it exists within a custom heap, it can allow an attacker to bypass protections found in standard memory.
The hunt for the vulnerability began when Vectra noticed an email from an external researcher who attempted to sell a proof-of-concept exploit to Hacking Team. The email described an exploitable use-after-free bug in IE 11.
While Hacking Team declined to buy the PoC, the email gave enough information for Vectra researchers to find and analyze the bug. After approaching Hacking Team, the researcher may have gone elsewhere to sell the bug, and if successful it may have been exploited in the wild.
Remediation has been announced today in Microsoft’s Security Bulletin.