All the latest UK technology news, reviews and analysis


Microsoft says IE zero-day fix on the way

19 Sep 2012
Microsoft logo

Microsoft is looking to ease user fears over high-profile vulnerability in Internet Explorer, promising it will have a fix available later this week.

The company confirmed it will be posting a fix to addresses the remote code execution vulnerability in IE 7 and IE 8 for 32-bit Windows XP systems. The fix will be an 'out of band' update as the company is not slated to release its next monthly update until 9 October.

"There have been an extremely limited number of attacks — the vast majority of Internet Explorer users have not been impacted," Microsoft Trustworthy Computing director YunSun Wee said in a statement released by the company late Tuesday.

"We are working on an easy-to-use, one-click fix that will be released in the next few days, but in the meantime we recommend customers make sure their anti-virus software is up-to-date."

The flaw, which had previously been unknown, has been actively exploited in recent days by a cybercriminal gang to perform remote Trojan downloads on targeted systems.

According to researchers, the attackers are actively targeting victims with specially-crafted .swf files and using sophisticated techniques such as steering non-vulnerable systems away to outside pages.

Since the attack was spotted, Microsoft has come under fire from security experts who have been advising users to stop using Internet Explorer in favour of a competing browser.

On Tuesday, the German BSI weighed in on the matter when it also suggested that users and administrators should temporarily abandon IE while Microsoft develops a fix.

Microsoft, meanwhile, has posted a series of tips for mitigating the flaw including limiting scripting permissions and installing the company's own browser security tools.

  • Comment  
  • Tweet  
  • Google plus  
  • Facebook  
  • LinkedIn  
  • Stumble Upon  
Shaun Nichols
About

Shaun Nichols is the US correspondent for V3.co.uk. He has been with the company since 2006, originally joining as a news intern at the site's San Francisco offices.

More on Security
What do you think?
blog comments powered by Disqus
Poll

Green IT poll

How important is it to your business that a cloud provider uses renewable energy like solar or wind to power their data centres?
20%
6%
4%
2%
68%

Popular Threads

Powered by Disqus
Galaxy S5 vs Nexus 5 head to head review front

Galaxy S5 vs Nexus 5 video review

We compare Samsung and Google's top devices

Updating your subscription status Loading
Newsletters

Get the latest news (daily or weekly) direct to your inbox with V3 newsletters.

newsletter sign-up button
hpv3may

Getting started with virtualisation

Virtualisation can help you reduce costs, improve application availability, and simplify IT
management. However, getting started can be challenging

ibmv3may

Converting big data and analytics insights into results

Successful leaders are infusing analytics throughout their organisations to drive smarter decisions, enable faster actions and optimise outcomes

ASP.NET MVC, C# Developer - World Class Entertainment Company

ASP.NET MVC, C# Developer (.NET, C#.NET, dot NET, Web...

C# Developer - Financial Consultancy - Limited Travel - London

C# Developer (.NET, ASP.NET, C#.NET, dot NET, Web Application...

.NET Developer, ASP.NET, C# - Computer Gaming Company - London

.NET Developer (ASP.NET, C#, C#.NET, VB.NET, dot NET...

EMEA Training Manager

An EMEA Training Manager for Tax Software is required...
To send to more than one email address, simply separate each address with a comma.