Microsoft pushes emergency patch for Internet Explorer
Posted on 17 Dec 2008 at 08:35
Microsoft will break its traditional patch cycle to push out a fix for the Internet Explorer exploit.
The vulnerability stems from a memory corruption error in the handling of DHTML data bindings, and allows hackers to remotely execute code when the browser crashes. Hackers have been exploiting the vulnerability for over a week, with attacks initially coming from a number of Chinese-hosted porn sites.
That changed this weekend when Microsoft reported a "huge increase" in the number of attacks, as hackers began using SQL injection to corrupt legitimate sites. Trend Micro believes over 10,000 sites have been compromised to take advantage of the exploit, and has warned that the figure is "quickly increasing in number."
Evidence suggests the exploit is being mainly used to steal videogame passwords, though experts have warned it could be used to steal other personal information.
The vulnerability is specifically targeted at Internet Explorer 7, undoubtedly due to its huge user base. However, it's known to affect all versions.
The severity of the issue is evident in Microsoft's decision to break its own monthly patch schedule. It is only the second time in 18 months the company has felt the need to do so.
The patch will be rolled out through automatic updates and the Microsoft Download Center later today.
Author: Stuart Turton
advertisement
- Need a bit of extra Christmas cash? Grass up your boss, says BSA
- Photoshop Mobile on Android review: first look
- ATI Radeon HD 5970: 42% more expensive in the UK
- Office 2010 Beta – 32-bit or 64-bit – The Choice is Clear
- Why Britain's watchdogs have fewer teeth than goldfish
- Tabbed documents: how to make Office 2010 great
- Outlook 2010 People Pane – does it spell death to Xobni
- Microsoft Outlook 2010 screenshots
- Co-Authoring in Word 2010 and SharePoint Foundation 2010
- Microsoft Outlook 2010 screenshots: Backstage view
- ZoneAlarm Internet Security Suite
- Webroot Internet Security Essentials
- Trend Micro Internet Security
- PC Tools Internet Security 2009
- Panda Internet Security 2009
- Norton Internet Security 2009
- Kaspersky Internet Security 2009
- F-Secure Internet Security 2009
- AVG Internet Security 8
- BullGuard Internet Security 8.5
- SMC ADSL2 Barricade-N Pro
advertisement
Printed from www.pcpro.co.uk


