Microsoft releasing emergency patch for perilous IE flaw

This section for technical support that does not fit anywhere else

Microsoft releasing emergency patch for perilous IE flaw

Postby cas » Wed Dec 17, 2008 8:23 am

SAN FRANCISCO (AFP) — Microsoft will release an emergency patch on Wednesday to fix a perilous software flaw allowing hackers to hijack Internet Explorer browsers and take over computers.

The US software giant said on Tuesday that in response to "the threat to customers" it immediately mobilized security engineering teams worldwide to deliver a software cure "in the unprecedented time of eight days."

According to researchers at software security firm Trend Micro, attacks based on the vulnerability in the world's most popular Web browser are spreading "like wildfire" with millions of computers already compromised.

Microsoft typically releases patches for its software on the second Tuesday of each month and rushing this fix to computer users out-of-cycle is testimony to the severe danger of the threat, according to Trend Micro.

"When the patch is released people should run, not walk, to get it installed," said Trend Micro advanced threat researcher Paul Ferguson.

"This vulnerability is being actively exploited by cyber-criminals and getting worse every day."

Trend Micro has identified about 10,000 websites that have been infected with malicious software that can be surreptitiously slipped into visitors' unprotected IE browsers to take advantage of the flaw.

A major Internet portal in Taiwan is among the legitimate websites unknowingly tainted with malicious software aimed at IE's weak spot, according to Ferguson.

Hackers can take control of infected computers, steal data, redirect browsers to dubious websites, and use machines for devious activities such as attacks on other networks, according to security specialists.

"What makes this so insidious is it takes advantage of a big gaping hole of IE, which has the largest install base of any browser on the market," Ferguson said.

IE is used on nearly three-quarters of the world's computers, according to industry statistics from November.

"At this time, we are aware only of attacks that attempt to use this vulnerability against Windows Internet Explorer 7," said Microsoft security response communications head Christopher Budd.

"Microsoft encourages customers to test and deploy this update as soon as possible. Microsoft's teams worked around the clock."

Ferguson said the flaw is being taken advantage of in "multiple versions" of IE not just the most current.

Trend Micro urges IE users to heed precautionary advice from Microsoft, or avoid using the browsers, until the patches are applied.

"There is a working flaw circulating in the criminal underground," Ferguson said. "It opens the window of opportunity that much wider to take advantage and there has not been real protection against it."

The "exploit" is similar to one used recently to steal user names, passwords and other information from people playing online games in China, according to Trend Micro.

A Chinese computer security firm that had discovered attacks taking advantage of the IE flaw released details last week after evidently thinking Microsoft had fixed the problem with routinely released software patches.

"It spread like wildfire from there," Ferguson said. "I guess they were trying to be responsible and share what they knew about what was going on, but they were mistaken about it being patched."


http://www.google.com/hostednews/afp/ar ... JEr_CovlNg
Image
User avatar
cas
 
Posts: 1090
Joined: Mon Dec 08, 2008 8:49 am
Top

Re: Microsoft releasing emergency patch for perilous IE flaw

Postby Mr. Chris » Wed Dec 17, 2008 4:40 pm

Just one more good reason I use Firefox. ;) Chris.
1)Gigabyte GA-990FXA-UD3, Phenom II 970, 8Gb G Skill Sniper 1866, EVGA GTX470SC, 2x 500Gb SATA II RAID 0, Win 7 Ultimate 64 bit RTM
2) AX78, Phenom 9500, 2Gb OCZ PC6400, EVGA 9800GTX+, CDRW, XP Pro SP2
3) AX78, Phenom 9600, 2Gb OZC PC6400, EVGA 9800GTX, CDRW/DVD, CM CP600PCAR 600W, XP Pro Sp2

If you're not living on the edge, you are taking up too much room
User avatar
Mr. Chris
Site Admin
 
Posts: 2419
Joined: Fri Nov 21, 2008 4:47 pm
Location: Southern California
Top

Re: Microsoft releasing emergency patch for perilous IE flaw

Postby BlueMonster » Fri Dec 19, 2008 2:33 am

Mr. Chris wrote:Just one more good reason I use Firefox. ;) Chris.


Downloaded this update today, Great stuff, Thanks!! CAS!! Much improved IE7, IMO.

Blue

Important Update, formerly know as HOTFIX...LOL :lol:

Never have liked anything but MS IE, Myself, though FireFox is I'm sure more popular.
User avatar
BlueMonster
 
Posts: 2158
Joined: Fri Nov 21, 2008 5:08 pm
Location: San Francisco Bay Area
Top

Re: Microsoft releasing emergency patch for perilous IE flaw

Postby cas » Fri Dec 19, 2008 3:51 am

BlueMonster wrote:
Mr. Chris wrote:Just one more good reason I use Firefox. ;) Chris.


Downloaded this update today, Great stuff, Thanks!! CAS!! Much improved IE7, IMO.

Blue

Important Update, formerly know as HOTFIX...LOL :lol:

Never have liked anything but MS IE, Myself, though FireFox is I'm sure more popular.


Nah.... don't mention. MS use to patch and update their browser, so i find it doesn't make much differences, though i knew lot's of peep uses firefox but i still prefer IE :tease:
Image
User avatar
cas
 
Posts: 1090
Joined: Mon Dec 08, 2008 8:49 am
Top

Re: Microsoft releasing emergency patch for perilous IE flaw

Postby randomizer » Sun Dec 21, 2008 8:39 am

IE7 crashes whenever I open Tom's Hardware's site. But it's a "quiet" crash, no error messages or anything, the process just terminates.
i7 920 D0 @ Stock | 3x2GB G.Skill DDR3-1333 | 640GB WD Caviar Black | GTX 275 | MSI X58 Pro-E | Corsair HX-520
User avatar
randomizer
 
Posts: 318
Joined: Sat Nov 22, 2008 6:59 am
Top

Re: Microsoft releasing emergency patch for perilous IE flaw

Postby Greybear » Sun Dec 21, 2008 3:56 pm

Drop a link to the exact page your crashing at.
Greybear
 
Posts: 925
Joined: Sun Nov 23, 2008 7:30 pm
Top

Re: Microsoft releasing emergency patch for perilous IE flaw

Postby honestjohn » Sun Dec 21, 2008 6:50 pm

randomizer wrote:IE7 crashes whenever I open Tom's Hardware's site. But it's a "quiet" crash, no error messages or anything, the process just terminates.


It opens fine for me on the main page. Same with a few of the other non-US sites as well. It probably has something to do with the ton of flash-ads they have going on, but as Greybear said a direct link may offer more insight.

Image
User avatar
honestjohn
 
Posts: 1082
Joined: Fri Nov 21, 2008 6:15 pm
Top

Re: Microsoft releasing emergency patch for perilous IE flaw

Postby randomizer » Sun Dec 28, 2008 10:05 am

Oops, forgot this thread. It seems to be fixed now, but it was pretty much whenever I went to an article it would crash.
i7 920 D0 @ Stock | 3x2GB G.Skill DDR3-1333 | 640GB WD Caviar Black | GTX 275 | MSI X58 Pro-E | Corsair HX-520
User avatar
randomizer
 
Posts: 318
Joined: Sat Nov 22, 2008 6:59 am
Top


Return to General Technical Support

Who is online

Users browsing this forum: No registered users and 0 guests