Menu
With Web attacks increasing, Microsoft fixes IE bug

With Web attacks increasing, Microsoft fixes IE bug

Microsoft has released a critical patch for its IE browser.

Security experts say that Web surfers should immediately install a new bug-fix for Microsoft's Internet Explorer browser, released Wednesday morning.

The flaw, which was accidentally made public by Chinese security researchers just over a week ago, has been used in a growing number of Web-based attacks over the past few days. Criminals have posted attack code that exploits this flaw on thousands of Web sites so far, according to Rick Howard, intelligence director with Verisign's iDefense group. Verisign has now seen six variants of the attack software, all of which attempt to steal Chinese online gaming credentials.

Often the attack is launched through a hidden iFrame component that is surreptitiously put on a Web site. Verisign has even spotted one such iFrame attack on a legitimate financial institution's Web site, Howard said. "The volume of iFrames deploying this thing is really high."

The flaw lies in the way Internet Explorer's data-binding function works, Microsoft said. When the browser is attacked it will crash, corrupting the computer's memory and allowing the criminal to run unauthorized software.

Because Internet Explorer is used by about 70 percent of Web surfers, this attack code will probably show up in widely used malicious software toolkits "very shortly," Howard said.

Other security companies agreed with Verisign's assessment. "Microsoft's latest IE out-of-band patch release needs to be installed right away," said Shavlik Technologies in a statement. "The number of infected Web sites is growing at an alarming rate -- even people visiting legitimate Web sites are getting hacked with this exploit."

The flaw is so serious, in fact, that Microsoft took the unusual step of issuing its security fix weeks ahead of schedule. Typically Microsoft releases security patches just once a month in order to simplify the lives of system administrators. Its next set of updates is due Jan. 13.

Criminals could also launch their attacks via e-mail, by sending victims maliciously encoded HTML documents, although this type of attack has not been reported.

According to Microsoft Australia, the impact on Australian customers has been "minimal".

Microsoft's patch is for users of IE version 5 and up.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Internet Explorer

Featured

Slideshows

Meet the leading female front runners of the Kiwi channel

Meet the leading female front runners of the Kiwi channel

Reseller News honoured the leading female front runners of the New Zealand channel at the 2018 Women in ICT Awards (WIICTA) in Auckland. The awards honoured standout individuals across seven categories, spanning Entrepreneur; Innovation; Rising Star; Shining Star; Community; Technical and Achievement.

Meet the leading female front runners of the Kiwi channel
Meet the top performing customer-centric Microsoft channel partners

Meet the top performing customer-centric Microsoft channel partners

Microsoft honoured leading partners across the channel following a year of customer innovation and market growth in New Zealand. The 2018 Microsoft Partner Awards recognised excellence within the context of the end-user, spanning a host of emerging and established providers.

Meet the top performing customer-centric Microsoft channel partners
Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Show Comments