Microsoft Rushes to Patch 'Serious' Flaw in IE6, IE7
Microsoft is rushing to patch what's described as a serious flaw in Internet Explorer 6 and Internet Explorer 7 after the code for exploiting the security hole was published online.
Microsoft has announced that it is currently testing a patch for an IE6 and IE7 flaw after the exploitation code was made public by Israeli security researcher Moshe Ben Abu. Though the next Patch Tuesday is not until early April, Microsoft's Jerry Bryant said the release of the code means there would likely be a patch before then.
"We have seen speculation that Microsoft might release an update for this issue out-of-band," Bryant, a senior communications manager with the Microsoft Security Response Center (MSRC) wrote in a blog post. "I can tell you that we are working hard to produce an update which is now in testing," he said, adding, " This is a critical and time intensive step of the process as the update must be tested against all affected versions of Internet Explorer on all supported versions of Windows."
Microsoft warned users of the vulnerability last week, only to have research Moshe Ben Abu release the exploitation code the next day. The vulnerability is said to exist due to an invalid pointer reference being used within IE. MS says it is possible for the invalid pointer to be accessed after an object is deleted.
"In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution," Microsoft said in its advisory.
Microsoft has released an automated workaround but the Fix It is only effective for users running Windows XP and Windows Server 2003.
Read Bryant's full blog post here. Click here to access the Fix It page.
- Say Goodbye to Your iPad When the Battery Fails
- Google's Plans to Leave China are 99.9% Certain
- Inno3D's GeForce GTX 480 Boxed for Shipping
- HP Spends $40,000,000 to Show You It's Amazing
- Portal's GLaDOS Shows New Blue Screen of Death
- DRM Damages a Game's Value, Says Valve Boss
- New Deus Ex 3: Human Revolution Trailer at GDC
- Crysis 2 Gameplay Shown at GDC 2010
- EVGA Shows GeForce GTX 480, 470 Boxes Too
- Kingston 2400MHz DDR3 'World's Fastest Memory'
- FCC, DoJ Investigate NCB, Comcast Merger
- Top Ten BitTorrented Movies Last Week
- Pirate Bay Founder on Prison, Coke, Porn, Google
- Build Your Own: Tom's Hardware's BestConfigs, Updated!
- PS Move Precise Enough to Control StarCraft
- Nvidia Announces 3DTV Play for GeForce 3D Vision
- Gigabyte's USB 3.0 Contest is Open to the World
- Apple Hires 'Wearable Technologies' Expert





