Login

Username:

Password:

 
Lost Password?
Register now!


Did you know?
What is SafeInput?



Random FAQ
Is there a fee to becoming a partner?

Identity & Security : Emergency Internet Explorer patch issued overnight
Posted by glm on 2008/12/22 15:16:37 (20 reads)





By :Angela Moscaritolo


Dec 18, 2008 11:03 AM




Users are encouraged to patch their systems immediately with an out-of-band fix from Microsoft for a major Internet Explorer vulnerability.

As promised, Microsoft on Wednesday issued an out-of-band emergency fix for Internet Explorer (IE) to patch a security vulnerability that affects all supported versions of Microsoft's web browser.

The vulnerability involves a data-binding issue and is currently being exploited in the wild -- distributed via SQL injection, according to the SANS Internet Storm Center (ISC) in a post.

“Microsoft's latest IE out-of-band patch release needs to be installed right away,” Eric Schultze, CTO of Shavlik Technologies, wrote in an email to SCMagazineUS.com on Wednesday. “The number of infected websites is growing at an alarming rate -- even people visiting legitimate websites are getting hacked with this exploit.”

The vulnerability was announced last week and over the weekend exploits gained momentum. There have been SQL injections on about 6,000 websites. The injected code leads to the download of a trojan that modifies files on an infected user's PC and downloads other malicious files.

Another exploit aiming to steal information from Chinese online gamers was identified, TrendLabs said in a blog post Wednesday.

"Microsoft played down the issue on Patch Tuesday, but by the end of the week we in the security community had proven in our own labs that it was not just an IE 7 issue, and, in fact, it impacted multiple versions of IE -- even beta Version 8 – across multiple MS operating systems," Paul Henry, forensic analyst at Lumension Security, said in an email to SCMagazineUS.com on Wednesday.

Shavlik said Microsoft probably decided the issue warranted an out-of-band patch based on the rapid rate of user infection and because attackers were loading the exploit on legitimate websites so users who visit seemingly innocent websites might also be hit.

"The underlying exploit was actively being used in the wild and damage was mounting," Henry said.

See original article on scmagazineus.com



Source from:Secure Computing Magazine







Other articles
2009/2/4 23:20:16 - Cloud computing is a storage spot for malware
2009/2/4 23:20:15 - Microsoft responds to Windows 7 security gripe
2009/2/4 23:20:12 - Web identity hijacking on the rise
2009/2/4 23:20:12 - Google glitch puts surfers in a quandary
2009/2/4 23:20:11 - Facebook plays down privacy concerns
2009/2/4 23:20:10 - Australian Computer Society to use Sophos security solution
2009/2/4 23:20:09 - Google working on fix for clickjacking vulnerability in Chrome
2009/2/4 23:20:08 - McAfee: Malware will use web and USB sticks to spread in 2009
2009/2/4 23:20:07 - With economy in tailspin, Monster discloses major breach
2009/2/4 23:20:06 - OS X 'pirate' trojan resurfaces
2009/2/4 23:20:05 - IE 8 approaching on formal release
2009/2/4 23:20:04 - Companies warned over use of Netbooks
2009/2/4 23:20:03 - Trend Micro signs up with BigFix
2009/2/4 23:17:08 - Banks urged to change security policies
2009/2/4 23:17:08 - Heartland incident provides opportunity to standardise data breach notification laws

The comments are owned by the poster. We aren't responsible for their content.

Articles