Microsoft to Release Emergency Patch for Critical IE Flaw

December 17, 2008 by PatB | 3 comments

According to Brian Krebs’ Security Fix blog, Microsoft is releasing an out of band patch to fix the critical flaw in all versions of Internet Explorer that we discussed on [GAS] last week.  This is great news.  While the number of home computers compromised by this attack is only about 1 in 500, security companies have noted sharp increases in the numbers of webservers that are being compromised to serve the malware to spread the infections.

Krebs writes:

Microsoft is signaling that it plans to ship an emergency software update on Wednesday to fix a dangerous security hole in its Internet Explorer Web browser that thousands of compromised Web sites have been using to install malicious software.

Microsoft says the critical flaw is present in all versions of IE, from IE5 all the way up through IE8 Beta 2.  Microsoft estimated that about 0.2 percent of Windows users worldwide may have been exposed to Web sites containing exploits that try to attack this vulnerability.

While one in every 500 IE users may not sound like a large number, Microsoft said the frequency of attacks is increasing dramatically.

Signs that hackers were exploiting an unpatched flaw in all versions of IE showed up the day after this month’s Patch Tuesday. Attackers have begun using this day for exploitation as it gives them the longest lead time until Microsoft gets around to fixing it.

Microsoft has done an excellent job turning out this patch in an emergency.  But the hackers will be back at it next week looking for new methods of exploit.  And the patch dance goes onward.

Share and Enjoy:
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • MySpace
  • FriendFeed
  • del.icio.us
  • Google Bookmarks
Related Posts:
  1. Microsoft Patch Day: 7 Bulletins, 19 Flaws
  2. Microsoft Promises ‘Backwards Incompatibility’ On Internet Explorer 8.0
  3. It’s Microsoft Patch Day… Again!
  4. Half Million Microsoft Servers Hacked
Cool posts on other blogs:
Did you enjoy this post? If so, subscribe to the geeksaresexy RSS feed.

RSS feed

3 Comments »

Comment by Simon
2008-12-18 17:25:55

has anyone had any problems with this patch? I updated a SBS 203 server remotely last night and on reboot the server died (and I had to go out an manual get it online).

Anyone had similar experiences?

Comment by Kiltak
2008-12-18 18:12:53

Deployed it on 80 xp systems today with no problems… didn’t do the servers yet. (We’re running Windows 2003 sp2)

 
 
Comment by PatB
2008-12-18 23:13:54

I noticed that it took a while to release the patch for IE8.2 beta. Other than that, no issues reported by my IT teams.

 
Name (required)
E-mail (required - never shown publicly)
URI
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

Trackback responses to this post


| [Geeks are Sexy] Privacy Policy | Legal Disclaimer |