All the latest UK technology news, reviews and analysis


Microsoft says IE zero-day fix on the way

19 Sep 2012
Microsoft logo

Microsoft is looking to ease user fears over high-profile vulnerability in Internet Explorer, promising it will have a fix available later this week.

The company confirmed it will be posting a fix to addresses the remote code execution vulnerability in IE 7 and IE 8 for 32-bit Windows XP systems. The fix will be an 'out of band' update as the company is not slated to release its next monthly update until 9 October.

"There have been an extremely limited number of attacks — the vast majority of Internet Explorer users have not been impacted," Microsoft Trustworthy Computing director YunSun Wee said in a statement released by the company late Tuesday.

"We are working on an easy-to-use, one-click fix that will be released in the next few days, but in the meantime we recommend customers make sure their anti-virus software is up-to-date."

The flaw, which had previously been unknown, has been actively exploited in recent days by a cybercriminal gang to perform remote Trojan downloads on targeted systems.

According to researchers, the attackers are actively targeting victims with specially-crafted .swf files and using sophisticated techniques such as steering non-vulnerable systems away to outside pages.

Since the attack was spotted, Microsoft has come under fire from security experts who have been advising users to stop using Internet Explorer in favour of a competing browser.

On Tuesday, the German BSI weighed in on the matter when it also suggested that users and administrators should temporarily abandon IE while Microsoft develops a fix.

Microsoft, meanwhile, has posted a series of tips for mitigating the flaw including limiting scripting permissions and installing the company's own browser security tools.

  • Comment  
  • Tweet  
  • Google plus  
  • Facebook  
  • LinkedIn  
  • Stumble Upon  
Shaun Nichols
About

Shaun Nichols is the US correspondent for V3.co.uk. He has been with the company since 2006, originally joining as a news intern at the site's San Francisco offices.

More on Security
What do you think?
blog comments powered by Disqus
Poll

BYOD vs CYOD vs BYOC poll

Which approach is your firm taking to managing employees' mobile devices?
23%
14%
4%
17%
30%
12%

Popular Threads

Powered by Disqus
Galaxy S5 vs iPhone 5S vs Nexus 5 showdown

Galaxy S5 vs iPhone 5S vs Nexus 5

We speed test three of the most popular smartphones

Updating your subscription status Loading
Newsletters

Get the latest news (daily or weekly) direct to your inbox with V3 newsletters.

newsletter sign-up button
hpv33

Data protection: the key challenges

Deduplication is a foundational technology for efficient backup and recovery

rdc2

iPad makes its mark in the enterprise

The iPad can become a supercharged unified communications endpoint, allowing users to enhance their productivity

Digital Project Manager - Creative Technology House

Digital Project Manager - Creative Technology House Henley...

SQL Database Adminstrator (DBA) SQL 2012, SSIS, Windows 2012

SQL Database Adminstrator (DBA) SQL 2012, SSIS, Windows...

SharePoint Lead Developer - SharePoint 2013, C#, .Net

SharePoint Lead Developer – SharePoint 2013, C#, .Net...

Infrastructure Analyst - Storage, SAN, EMC, VMWare, Exchange

Infrastructure Analyst - Storage, SAN, EMC, VMWare, Exchange...
To send to more than one email address, simply separate each address with a comma.