Here’s a new spin on things. New security risks with IE are not new, but a new exploit actually requires Firefox to be installed on the machine. If Firefox is not installed, then the bug doesn’t exist. Essentially, it requires the user to click a malicious link in IE, which will then pass code to Firefox to execute. Roundabout hack, but I am more curious as to why someone would use IE when Firefox is installed!
“The underlying issue is the number of Web sites that are hosting malicious code,” Ronald O’Brien, a senior security analyst for Sophos, told LinuxInsider. “We know there are tens of thousands of Web sites that have been created that lack basic security aspects to them, and as such are readily hacked for the purpose of inserting malicous code onto them.”
Source: Linux Insider