
An adware purveyor has apparently used two previously unknown security flaws in Microsoft’s Internet Explorer browser to install a toolbar on victims’ computers that triggers pop-up ads. One flaw lets an attacker run a program on a victim’s machine, while the other enables malicious code to “cross zones,” or run with privileges higher than normal.