Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 18-12-2008, 08:53 PM   #1 (permalink)
Apprentice
 
Worried From Bugs's Avatar
 
Join Date: Nov 2008
Location: Varanasi
Posts: 60
Arrow Microsoft issues patch to fix IE




Microsoft has issued a security patch to fix a critical vulnerability in its Internet Explorer browser which it said has attacked over 2m Windows users.
The flaw is believed to have already infected as many as 10,000 websites.
The "zero day" exploit let criminals take over victims' computers by steering them to infected websites.

Microsoft's Christopher Budd said the software giant "encourages all IE customers to test and deploy this update as soon as possible".

He also said the threat led Microsoft to mobilise security engineering teams worldwide to deliver a software cure "in the unprecedented time of eight days".

The company's security response team said the patch consists of more than 300 distinct updates for more than half-a-dozen versions of IE in around 50 languages.
"Even with that, the release Emergency Response process isn't over," said Security Response Alliance director Mike Reavey.

"There is additional support to customers and additional refinement of our product development efforts."

Microsoft stressed that the flaw was proven to exist only in IE 7 on all applicable versions of Windows, but that IE 6 and the "beta" release of IE 8 were "potentially vulnerable".

Users who have automatic updates turned on will receive the patch over the next 24 hours while others can access it via a download.

'Wildfire'
The AZN Trojan has been making the rounds since the beginning of December but became public knowledge in the last week . Unlike other exploits, users only have to visit a malicious site with Trojans or other malware in order to become contaminated.

Once an infected web page is opened, malicious downloaders are installed on the computer designed to record keystrokes and steal passwords, credit card details and other financial information.

The sites affected are mostly Chinese and have been serving up programmes to steal passwords for computer games which can then be sold for cash on the black market.
Internet Explorer is the world's most widely used web browser with nearly three quarters of the market share.

Microsoft estimated that one in every 500 Windows users had been exposed to sites that tried to exploit the flaw and the number of victims was increasing at a rate of 50% daily.

Researchers at the software security firm Trend Micro said attacks were spreading "like wildfire".

"This vulnerability is being actively exploited by cyber-criminals and getting worse every day," said the company's advanced threat researcher Paul Ferguson.
Microsoft labelled the bug as "critical," the most serious threat ranking in its four-step scoring programme.

Firefox update
The update is something of an unusual move for Microsoft and underscores the seriousness of the zero day flaw.

The company rarely issues security fixes for its software outside of its regular monthly patch updates.

Meanwhile Mozilla has released a scheduled update for its open source Firefox web browsers for at least 10 different vulnerabilities.

The bugs in the browser could have been "used to run attacker code and install software, requiring no user interaction beyond normal browsing," said Mozilla.
It is also reissuing calls for users to upgrade from Firefox 2.0 to Firefox 3.0 as soon as possible and said it is "not planning any further security and stability updates for Firefox 2".

This means Mozilla will no longer support the Firefox 2 browser against future online scams and attacks.

Last edited by Worried From Bugs; 13-07-2009 at 08:10 AM.
Worried From Bugs is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 18-12-2008, 09:01 PM   #2 (permalink)
Back!
 
red_devil's Avatar
 
Join Date: Jun 2007
Location: Bangalore
Posts: 513
Default Re: Microsoft issues patch to fix IE

I'm sure you didn't read this topic :

Microsoft plans quick fix for IE.
red_devil is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Hefty Apple Patch Set Tackles Leopard, Firewall Issues Gigacore Technology News 16 20-11-2007 07:09 PM
Microsoft’s Animated Cursor Patch Causes DLL Errors at Startup rakeshishere Technology News 2 09-04-2007 07:31 PM
Microsoft February Patch Tuesday: 12 security patches! Ankur Mittal Technology News 1 09-02-2007 10:04 AM
Critical Windows Patch Coming From Microsoft Sourabh Software Q&A 3 13-06-2005 08:35 PM
**Microsoft Patch Day Next Week-13 Patches to be released** techno_funky Software Q&A 5 05-02-2005 09:34 PM

 
Latest Threads
- by Who
- by abhidev
- by Tenida
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 10:14 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2