. Military Space News .
Microsoft releasing emergency patch for perilous IE flaw

by Staff Writers
San Francisco (AFP) Dec 16, 2008
Microsoft will release an emergency patch on Wednesday to fix a perilous software flaw allowing hackers to hijack Internet Explorer browsers and take over computers.

The US software giant said on Tuesday that in response to "the threat to customers" it immediately mobilized security engineering teams worldwide to deliver a software cure "in the unprecedented time of eight days."

According to researchers at software security firm Trend Micro, attacks based on the vulnerability in the world's most popular Web browser are spreading "like wildfire" with millions of computers already compromised.

Microsoft typically releases patches for its software on the second Tuesday of each month and rushing this fix to computer users out-of-cycle is testimony to the severe danger of the threat, according to Trend Micro.

"When the patch is released people should run, not walk, to get it installed," said Trend Micro advanced threat researcher Paul Ferguson.

"This vulnerability is being actively exploited by cyber-criminals and getting worse every day."

Trend Micro has identified about 10,000 websites that have been infected with malicious software that can be surreptitiously slipped into visitors' unprotected IE browsers to take advantage of the flaw.

A major Internet portal in Taiwan is among the legitimate websites unknowingly tainted with malicious software aimed at IE's weak spot, according to Ferguson.

Hackers can take control of infected computers, steal data, redirect browsers to dubious websites, and use machines for devious activities such as attacks on other networks, according to security specialists.

"What makes this so insidious is it takes advantage of a big gaping hole of IE, which has the largest install base of any browser on the market," Ferguson said.

IE is used on nearly three-quarters of the world's computers, according to industry statistics from November.

"At this time, we are aware only of attacks that attempt to use this vulnerability against Windows Internet Explorer 7," said Microsoft security response communications head Christopher Budd.

"Microsoft encourages customers to test and deploy this update as soon as possible. Microsoft's teams worked around the clock."

Ferguson said the flaw is being taken advantage of in "multiple versions" of IE not just the most current.

Trend Micro urges IE users to heed precautionary advice from Microsoft, or avoid using the browsers, until the patches are applied.

"There is a working flaw circulating in the criminal underground," Ferguson said. "It opens the window of opportunity that much wider to take advantage and there has not been real protection against it."

The "exploit" is similar to one used recently to steal user names, passwords and other information from people playing online games in China, according to Trend Micro.

A Chinese computer security firm that had discovered attacks taking advantage of the IE flaw released details last week after evidently thinking Microsoft had fixed the problem with routinely released software patches.

"It spread like wildfire from there," Ferguson said. "I guess they were trying to be responsible and share what they knew about what was going on, but they were mistaken about it being patched."

Share This Article With Planet Earth
del.icio.usdel.icio.us DiggDigg RedditReddit
YahooMyWebYahooMyWeb GoogleGoogle FacebookFacebook



Related Links
Cyberwar - Internet Security News - Systems and Policy Issues



Memory Foam Mattress Review
Newsletters :: SpaceDaily :: SpaceWar :: TerraDaily :: Energy Daily
XML Feeds :: Space News :: Earth News :: War News :: Solar Energy News


China defends censoring websites that break rules
Beijing (AFP) Dec 16, 2008
China defended Tuesday the blocking of websites it said violated Chinese law and urged Internet companies to respect its legal system.







  • Obama to tap Colorado senator for interior dept: reports
  • Russian warships bound for Cuba in new show of strength
  • Russian warships sail into Nicaragua political storm
  • Russian warship leaves Panama after historic visit

  • NKorea to remove 'paper companies' from economic zone
  • UN ministerial meeting on Iranian nuclear program
  • US, Jordan sign deal to prevent nuclear smuggling
  • SKorea says energy aid to NKorea to continue

  • Six killed in suspected US missile strike in Pakistan: official
  • US Navy Tests Seven Raytheon Standard Missile-2 Block IIIAs During Trials
  • NLOS-LS Team Completes Second Guided Test Flight Of PAM
  • Iran tests medium-range missile in naval war games

  • BMD Watch: MKV-L in free-flight hover test
  • Russia says US missile talks fail to solve 'serious differences'
  • US, Russia to discuss missile shield in Moscow
  • US, Russia to discuss missile shield in Moscow next week

  • Britain's environment minister concerned by Heathrow plan
  • Climate protesters cause chaos at British airport
  • Thompson Files: Protect U.S. aerospace
  • NASA studies pilot cognition

  • Russia mulls unprecedented Israel drones purchase
  • Raven UAS Certified By Italian Ministry Of Defense
  • Successful Autoland Of The F-16 Fighting Falcon
  • Navy Targets Unmanned Aircraft

  • Iraq cabinet wants all non-US foreign troops out by July
  • Saddam lawyer to defend Bush shoe attacker
  • Analysis: Gates upbeat on Iraq, slams Iran
  • Dogs of War: The Blackwater indictments

  • Amnesty warns against 'potentially lethal' Tasers
  • Thermal Curtains Will Offer Protection To Aircrews
  • TALON IV Engineer Takes The Soldier Out Of The Minefield
  • Airlift The Key To True Superpower Capability Part One

  • The content herein, unless otherwise known to be public domain, are Copyright 1995-2007 - SpaceDaily.AFP and UPI Wire Stories are copyright Agence France-Presse and United Press International. ESA Portal Reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement,agreement or approval of any opinions, statements or information provided by SpaceDaily on any Web page published or hosted by SpaceDaily. Privacy Statement