Microsoft will release an update to patch five flaws including a zero-day affecting Internet Explorer 9 and earlier versions.
Attackers could exploit the holes to hijack Windows machines and inject malware.
Microsoft, which issued a stop gap for the zero day, would release the fix around 3am tomorrow.
"[The] remote code execution vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated," Microsoft said in an advisory. The flaw could corrupt memory and allow an attacker to execute arbitrary code.
Microsoft Trustworthy Computing director Yunsun Wee said the vulnerabilities affected a small number of customers.
"The potential exists, however, that more customers could be affected," he wrote.
The fix will be available through Windows Update and the company recommends users install it as soon as it is available. Users with automatic updates enabled on their PC won't need to take any action.
nCircle security operations director Andrew Storms said Microsoft was "light years ahead of other vendors in providing clear, consistent, valuable communication to their users on security issues".
This article originally appeared at scmagazineus.com
Copyright © SC Magazine, US edition
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED GOES EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @itnews.com.au to your white-listed senders.