IDNetters Forums

Technical News & Discussion => Windows News & Discussion => Topic started by: Rik on Mar 30, 2010, 09:47:01

Title: MS to release patch for IE7/7
Post by: Rik on Mar 30, 2010, 09:47:01
El Reg (http://www.theregister.co.uk/2010/03/29/ie_emergency_fix/) reports that:
QuoteMicrosoft has announced plans to release an out-of-sequence patch, designed to resolve a zero-day vulnerability in Internet Explorer.

A cumulative update to Internet Explorer (MS10-018) plugs a security hole in IE 6 and IE 7 exploited by hackers over recent weeks. The latest version of Microsoft's browser, IE 8, is not vulnerable to the flaw, which Microsoft first acknowledged was a problem on 9 March.

The iepeers.dll library is the weak spot - the flaw involving the handling of invalid values passed to the "setAttribute()" function. Exploits create a means to drop malware onto the PCs of victims, providing they visit booby-trapped websites using vulnerable versions of IE, as explained in our earlier story here.

Microsoft said in a statement that it had taken the unusual but not unprecedented step of releasing a patch outside its regularly Patch Tuesday update cycle after monitoring the situation and reaching the conclusion that "an out-of-band release is needed to protect customers". The update also includes fixes for nine other vulnerabilities in IE that Redmond had initially planned to release on 13 April. ®
Title: Re: MS to release patch for IE7/7
Post by: Simon on Mar 30, 2010, 10:46:21
:sigh:
Title: Re: MS to release patch for IE7/7
Post by: Rik on Mar 30, 2010, 10:52:27
Indeed.
Title: Re: MS to release patch for IE7/7
Post by: Den on Mar 30, 2010, 16:27:20
Serve people right for not moving up to IE8  ;D
Title: Re: MS to release patch for IE7/7
Post by: Steve on Mar 30, 2010, 18:23:55
They're still working on the IE8 one  ;D
Title: Re: MS to release patch for IE7/7
Post by: zappaDPJ on Mar 30, 2010, 18:39:53
 :lol: