
Internet attack trackers and antivirus companies warn that a flaw in Internet Explorer 7 (but not earlier versions) that Microsoft just patched last week is under attack in the wild. The attacks appear to be targeted and small-scale right now, but will likely grow.
Trend Micro describes a somewhat roundabout attack that starts with an e-mailed .doc file that, when opened, exploits the MS09-002 vulnerability to download and install remote-control backdoor malware.
Trend writes that this approach is likely part of a targeted attack. Such assaults typically involve more legwork on the part of crooks to construct a realistic spam message that may appear to come from a co-worker, for instance, and have a poisoned .doc or other file attached…
