Microsoft pushes emergency patch for Internet Explorer
By Stuart Turton
Posted on 17 Dec 2008 at 08:35
Microsoft will break its traditional patch cycle to push out a fix for the Internet Explorer exploit.
The vulnerability stems from a memory corruption error in the handling of DHTML data bindings, and allows hackers to remotely execute code when the browser crashes. Hackers have been exploiting the vulnerability for over a week, with attacks initially coming from a number of Chinese-hosted porn sites.
That changed this weekend when Microsoft reported a "huge increase" in the number of attacks, as hackers began using SQL injection to corrupt legitimate sites. Trend Micro believes over 10,000 sites have been compromised to take advantage of the exploit, and has warned that the figure is "quickly increasing in number."
Evidence suggests the exploit is being mainly used to steal videogame passwords, though experts have warned it could be used to steal other personal information.
The vulnerability is specifically targeted at Internet Explorer 7, undoubtedly due to its huge user base. However, it's known to affect all versions.
The severity of the issue is evident in Microsoft's decision to break its own monthly patch schedule. It is only the second time in 18 months the company has felt the need to do so.
The patch will be rolled out through automatic updates and the Microsoft Download Center later today.
From around the web
advertisement
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- ZoneAlarm Internet Security Suite
- Webroot Internet Security Essentials
- Trend Micro Internet Security
- PC Tools Internet Security 2009
- Panda Internet Security 2009
- Norton Internet Security 2009
- Kaspersky Internet Security 2009
- F-Secure Internet Security 2009
- AVG Internet Security 8
- BullGuard Internet Security 8.5
advertisement
