Microsoft to Release Emergency Patch for Critical IE Flaw

December 17, 2008 by PatB | 3 comments

According to Brian Krebs’ Security Fix blog, Microsoft is releasing an out of band patch to fix the critical flaw in all versions of Internet Explorer that we discussed on [GAS] last week.  This is great news.  While the number of home computers compromised by this attack is only about 1 in 500, security companies have noted sharp increases in the numbers of webservers that are being compromised to serve the malware to spread the infections.

Krebs writes:

Microsoft is signaling that it plans to ship an emergency software update on Wednesday to fix a dangerous security hole in its Internet Explorer Web browser that thousands of compromised Web sites have been using to install malicious software.

Microsoft says the critical flaw is present in all versions of IE, from IE5 all the way up through IE8 Beta 2.  Microsoft estimated that about 0.2 percent of Windows users worldwide may have been exposed to Web sites containing exploits that try to attack this vulnerability.

While one in every 500 IE users may not sound like a large number, Microsoft said the frequency of attacks is increasing dramatically.

Signs that hackers were exploiting an unpatched flaw in all versions of IE showed up the day after this month’s Patch Tuesday. Attackers have begun using this day for exploitation as it gives them the longest lead time until Microsoft gets around to fixing it.

Microsoft has done an excellent job turning out this patch in an emergency.  But the hackers will be back at it next week looking for new methods of exploit.  And the patch dance goes onward.

Sharing is Sexy!
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • MySpace
  • FriendFeed
  • del.icio.us
  • Google Bookmarks
  • email
Related Posts:
  1. Microsoft Patch Day: 7 Bulletins, 19 Flaws
  2. Microsoft Promises ‘Backwards Incompatibility’ On Internet Explorer 8.0
  3. It’s Microsoft Patch Day… Again!
  4. Half Million Microsoft Servers Hacked
Cool posts on other blogs:
Did you enjoy this post? If so, subscribe to the geeksaresexy RSS feed.

3 Responses to “Microsoft to Release Emergency Patch for Critical IE Flaw”

  1. Simon says:

    has anyone had any problems with this patch? I updated a SBS 203 server remotely last night and on reboot the server died (and I had to go out an manual get it online).

    Anyone had similar experiences?

  2. PatB says:

    I noticed that it took a while to release the patch for IE8.2 beta. Other than that, no issues reported by my IT teams.

Leave a Reply


| [Geeks are Sexy] Privacy Policy | Legal Disclaimer |