All the latest UK technology news, reviews and analysis

France joins Germany in call to dump IE

by Phil Muncaster

More from this author

18 Jan 2010

Comments: 4

  • Tweet this
Internet Explorer
Exploit code for the IE flaw is already on the internet

The pressure on Microsoft to release an out-of-cycle patch for an IE flaw which allowed Chinese hackers to attack Google's systems continues to grow, after authorities in France joined the German government in urging citizens to use an alternative browser.

Microsoft admitted late last week that the hack of Google's systems revealed on Tuesday was caused by a vulnerability in version 6 of its popular browser.

"The vulnerability exists as an invalid pointer reference within Internet Explorer," read a Microsoft security advisory.

"It is possible under certain conditions for the invalid pointer to be accessed after an object is deleted. In a specially crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution."

It later emerged that the exploit code for the flaw had made its way onto the internet, increasing the likelihood of copycat attacks.

The French and German authorities are now urging their citizens to use an alternative browser until the flaw is fixed, and the pressure on Microsoft to release an out-of-cycle patch is growing.

However, Microsoft is continuing to advise users to upgrade to the latest version of the browser, which appears to be unaffected by the vulnerability.

Graham Cluley, senior technology consultant at security vendor Sophos, warned that switching browsers may cause more problems than it solves in many cases.

"If your IT department doesn't already formally support an alternative brow ser, and if your users aren't already familiar with the other browser, you may be causing more problems than it's worth by summarily switching browsers," he wrote in a blog posting today.

"You may also have web-based applications that don't work well, or even at all, unless they are accessed with Internet Explorer. That's not going to be good for productivity. And finally, what if your replacement browser itself turns out to contain a vulnerability? Are you going to switch again?"

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Web C# ASP.NET Developer (Equity or Mutual Funds) London

Web C# ASP.NET Developer (Equity or Mutual Funds) London...

Senior Exploratory Tester - Selenium, Java, AJAX, WEB

Senior Exploratory Tester - Selenium, Java, AJAX, WEB...

SQL DBA/ Data Architect (T-SQL, SSIS, ETL) - Derivatives

SQL DBA/ Data Architect (T-SQL, SSIS, ETL) - Derivatives...

Test Analyst (Web, QTP, VB.NET, SQL) Wolverhampton

Test Analyst (Web, QTP, Test Director, VB.NET, SQL...

To send to more than one email address, simply separate each address with a comma.