Home Malware Programs Trojans Exp/20121889-A

Exp/20121889-A

Posted: June 20, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 63
First Seen: June 20, 2012
OS(es) Affected: Windows

Exp/20121889-A is one detection label for an as-of-yet-unpatched exploit that allows arbitrary script to run on websites that viewed with Internet Explorer. Although this exploit can be used for various attacks, expected consequences focus on drive-by-downloads or drive-by installations that install malicious software on the relevant PC. While Microsoft hasn't yet issued a security patch to close the Exp/20121889-A exploit or its associated exploit Sus/20121889-A, PC security companies have been scrambling to update their protection against this latest form of online attack. As long as you keep your security software updated and available to detect live attacks, your computer should be safe from Exp/20121889-A, which may be used to install virtually any type of harmful software – including rogue AV scanners, browser hijackers, Trojans or worms.

Exp/20121889-A: the Real Price of Using a Popular Web Browser

Exp/20121889-A is a form of web page-hosted content that's designed strictly for Internet Explorer; other web browsers can be considered safe from Exp/20121889-A and related exploits (such as Sus/20121889-A and Troj/20121889-B). Exp/20121889-A attacks use the unpatched CVE-2012-1889 exploit to attack vulnerable computers by running unauthorized code. Once Exp/20121889-A is launched, Exp/20121889-A can execute malicious code with all the rights of its current user. Typically, this is used to install a PC threat on the computer in question, although it may also be exploited for other purposes. Since the only thing you need to do to warrant an Exp/20121889-A attack is to visit an Exp/20121889-A-hosting web page with IE, Exp/20121889-A attacks can easily result in severe infections without visible symptoms. At this time, Internet Explorer is incapable of protecting against this attack, although various anti-malware brands are striving to make up for this deficiency until such a time as Microsoft can issue a security patch. At least one website has already been confirmed to host Exp/20121889-A: a hacked medical company site.

Since Exp/20121889-A and closely-related PC threats have only had protection available since mid-June of 2012, you should make updating your anti-malware software a high priority, especially if their databases are older than the above date. Alternately, using other web browsers can also provide an adequate defense against Exp/20121889-A, which is based on a Microsoft Core Services vulnerability that isn't applicable to non-IE brands of browsers.

How to Tell If Your PC is Up for Grabs by Exp/20121889-A

Exp/20121889-A and related vulnerabilities may target various versions of Windows:

  • Windows 7
  • Windows Server 2008
  • Windows XP
  • Windows Server 2003
  • Windows Vista

As a high-level PC threat that's almost certain to be used for distributing various types of hostile software, Exp/20121889-A poses a high risk to any computer that's attacked by Exp/20121889-A. SpywareRemove.com malware researchers encourage you to scan your PC immediately after any suspected contact with Exp/20121889-A, since a successful attack is strongly indicative of the presence of additional PC threats on your hard drive.

Loading...