IDNetters Forums

Technical News & Discussion => Windows News & Discussion => Topic started by: Rik on Dec 17, 2008, 10:24:11

Title: MS issuing emergency patch for IE7/8
Post by: Rik on Dec 17, 2008, 10:24:11
El Reg (http://www.theregister.co.uk/2008/12/16/microsoft_ie_emergency_patch_warning_dec_16_2008/) reports that:

QuoteMicrosoft will push out an emergency security patch for Internet Explorer on Wednesday, addressing a critical security hole currently being exploited in the wild.

Redmond issued advanced notice for tomorrow's fix, describing the out-of-cycle patch as protection from "remote code execution."

Unscheduled updates are pretty rare for Microsoft, stressing the potentially serious nature of the flaw. Although the last time Microsoft broke it's update cycle was in late October – it was the first time it had done so in about 18 months.

The latest zero-day vulnerability stems from data binding bugs that allows hackers access to a computer's memory space, allowing attackers to remotely execute malicious code as IE crashes, Microsoft has said.

Although the exploit was at first contained to warez and porn sites hosted on a variety of Chinese domains, the malicious JavaScript code has since spread to more trusted sites though SQL injection. The flaw is primarily being used to steal video game passwords at present, but could potentially be used to retrieve more critical sensitive data from users as well.

The vulnerability is specifically targeted at surfers running IE 7, but it's also known to affect versions 5, 6, and 8 of the browser as well. All IE users are advised to install the update.

Microsoft's emergency patch will become available Wednesday at 1 PM EST (18:00 GMT) from auto-update and the Microsoft Download Center. A separate patch will be made available for those running IE8 Beta 2. ®
Title: Re: MS issuing emergency patch for IE7/8
Post by: Inactive on Dec 17, 2008, 11:17:01
Thanks Rik, I have just stopped using altogether for now.
Title: Re: MS issuing emergency patch for IE7/8
Post by: Rik on Dec 17, 2008, 11:30:19
Me too, but I keep it patched just in case. :)
Title: Re: MS issuing emergency patch for IE7/8
Post by: Sebby on Dec 17, 2008, 13:50:54
Same, Rik.
Title: Re: MS issuing emergency patch for IE7/8
Post by: BrianM on Dec 17, 2008, 20:29:30
Thanks Rik, I use IE7, just updated the patch,  :thumb: