This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Microsoft says IE zero-day fix on the way

by Shaun Nichols

19 Sep 2012

View Comments

  • Tweet this
Microsoft logo

Microsoft is looking to ease user fears over high-profile vulnerability in Internet Explorer, promising it will have a fix available later this week.

The company confirmed it will be posting a fix to addresses the remote code execution vulnerability in IE 7 and IE 8 for 32-bit Windows XP systems. The fix will be an 'out of band' update as the company is not slated to release its next monthly update until 9 October.

"There have been an extremely limited number of attacks — the vast majority of Internet Explorer users have not been impacted," Microsoft Trustworthy Computing director YunSun Wee said in a statement released by the company late Tuesday.

"We are working on an easy-to-use, one-click fix that will be released in the next few days, but in the meantime we recommend customers make sure their anti-virus software is up-to-date."

The flaw, which had previously been unknown, has been actively exploited in recent days by a cybercriminal gang to perform remote Trojan downloads on targeted systems.

According to researchers, the attackers are actively targeting victims with specially-crafted .swf files and using sophisticated techniques such as steering non-vulnerable systems away to outside pages.

Since the attack was spotted, Microsoft has come under fire from security experts who have been advising users to stop using Internet Explorer in favour of a competing browser.

On Tuesday, the German BSI weighed in on the matter when it also suggested that users and administrators should temporarily abandon IE while Microsoft develops a fix.

Microsoft, meanwhile, has posted a series of tips for mitigating the flaw including limiting scripting permissions and installing the company's own browser security tools.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

17%

55%

10%

9%

9%

Popular Threads

Powered by Disqus
Sony Xperia Z vs Apple iPhone 5

Sony Xperia Z vs Apple iPhone 5 head to head video review

V3 pits Sony's rugged flagship against Apple's premier handset

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

Android Developer (Java, Android SDK, Sync Framework, Maven)

Android, Java, SDK, Maven, Sync Framework, Fragments...

Change Analyst/manager-ITIL SC Security Cleared-South East

Change Analyst, ITIL v3, HP Service Manager, SC Security...

ASP.NET Developer

ASP.NET Developer - Applications developer / VB.NET or...

Low Latency C++ Developer (FIX, Multi-threading)

C++ Developer (Low Latency, Multi-threading, FPGA, TCP...

To send to more than one email address, simply separate each address with a comma.