Microsoft bugs give familiar creepy feeling

By

Microsoft is investigating newly discovered security flaws that could affect millions of users. Research outfit eEye highlighted the vulnerabilities, affecting Internet Explorer and Outlook, late last week.

According to eEye, the vulnerabilities could be exploited with very little user interaction, meaning if an exploit were created, it could be very effective.


Microsoft claimed it is already investing the vulnerabilities. "At this time, Microsoft is not aware of any malicious attacks attempting to exploit the reported vulnerabilities, and there is no customer impact based on this issue," a spokesperson said. "Upon completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a fix through a service pack, our monthly release process or an out-of-cycle security update, depending on customer needs."

Traditionally Microsoft releases monthly updates, but occasionally, if the need is urgent, rolls them out earlier.

Earlier this month SC revealed a new report claiming Internet Explorer was "unsafe" for 98 percent of 2004. The figure is in marked contrast to Microsoft's biggest rival in the web browser market, Mozilla's Firefox, which was only vulnerable for 15 percent of the year, the report claimed.

www.microsoft.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Microsoft knew of SharePoint security flaw in May, initial patch ineffective

Microsoft knew of SharePoint security flaw in May, initial patch ineffective

ACSC alerts to exploited MS SharePoint remote code execution flaw

ACSC alerts to exploited MS SharePoint remote code execution flaw

"PoisonSeed" attack does not bypass hardware MFA

"PoisonSeed" attack does not bypass hardware MFA

Qantas obtains court order to prevent third-party access to stolen data

Qantas obtains court order to prevent third-party access to stolen data

Log In

  |  Forgot your password?