Microsoft knew about IE flaw for months

Powered by SC Magazine
 

Told in September.

Microsoft knew about the critical flaw in Internet Explorer (IE) that was recently exploited by hackers to gain entry to the systems of Google and at least 20 other big name companies.

Redmond issued an out-of-cycle patch for the flaw yesterday, urging all IE users to apply the fix as soon as possible.

However, Microsoft security programme manager Jerry Bryant said in a blog posting yesterday: "When the attack discussed in Security Advisory 979352 was first brought to our attention on Jan 11, we quickly released an advisory for customers three days later.

"As part of that investigation, we also determined that the vulnerability was the same as a vulnerability responsibly reported to us and confirmed in early September."

The news will come as no surprise to many security watchers, although it highlights what some have described as an inadequate system of 'responsible disclosure'.

Last week, little-known Russian security firm Intevydis said that it will publish details of zero-day exploits in business software every day for the rest of January in protest at the private disclosure system which it believes is flawed.

Intevydis claimed that vendors usually sit on vulnerabilities that are disclosed in private, whereas they act faster if the disclosure is made public without prior knowledge.

"Our position on responsible disclosure policy has evolved, and now we do not support it because it is enforced by vendors and it allows vendors to exploit security researchers to do quality assurance work for free," the firm added in a blog posting.

Copyright ©v3.co.uk


Microsoft knew about IE flaw for months
 
 
 
Top Stories
First look: Microsoft Outlook for iOS
[Update] Office productivity suite for iOS completed with Outlook.
 
NewSat defaults on $26m in overdue Lockheed payments
Jabiru-1 satellite build hits further hurdles.
 
IBM denies plans to cut 112k jobs
But admits to further restructuring.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Microsoft Outlook is now on iPhone and iPad: why could this be useful?
Jan 30, 2015
Microsoft today released Office for Android and Outlook for iOS - complementing the other Office ...
Franchisees, here's something you should know about
Jan 23, 2015
You need to know the Code if you are a franchisee or franchisor as the penalties are significant.
Xero users rejoice! Quoting has finally arrived
Jan 23, 2015
It has taken years, but Xero has at last added integrated quoting to its online accounting software.
You can now get a no-contract wi-fi tablet from Telstra
Jan 17, 2015
Telstra has began selling wi-fi tablets out of contract without paying extra for cellular ...
Get your business ready for 2015: mobile payments
Jan 2, 2015
These handy apps from MYOB, Xero and others can reduce your administrative load and improve ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  36%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3086

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 982

Vote