Microsoft confirms IE 6, 7 and 8 contain an unpatched bug — or “zero-day” vulnerability — that is being used by attackers to hijack victims’ Windows computers. Engineers have released a preliminary workaround that will protect affected IE customers until the update is ready. The vulnerability was used by hackers to exploit Windows PCs whose owners visited the Council on Foreign Relations (CFR) think tank’s website. Older versions of IE, including 2011’s IE9 and this year’s IE10, are not affected.”]
Source: https://www.csoonline.com/article/2132696/microsoft-confirms-zero-day-bug-in-ie6–ie7-and-ie8.html

