iTnews

Another early patch from Microsoft?

By Frank Washkuch on Mar 27, 2006 10:49PM

A patch for recently discovered – and exploited – flaw in Microsoft Internet Explorer (IE) is scheduled to be a part of April’s Patch Tuesday release, but could be released earlier.

Posting on the Microsoft Security Response Center weblog early Monday morning, Stephen Toulouse, head of the response center, assured PC users that Redmond's research teams are working overtime on a patch for the flaw.

"I want to reiterate that the IE team has the update in process right now and if warranted we'll release that as soon as it's ready to protect customers (right now our testing plan has it ready in time for the April update release cycle)," he said, adding that users could scan their machines when visiting a Microsoft website.

So far, Microsoft is only aware of limited attacks, said Toulouse.

Pedro Bueno, posting on the SANS Institute's Internet Storm Center website, advised IE users that Microsoft's scan protects against only known malware with signatures.

SANS had also seen a substantial number of malicious sites take advantage of the flaw.

"Although they say that (they) are seeing only limited attacks, we have some reports of more than 100 sites (Saturday data) exploring this vulnerability to install bots, keyloggers...," said Bueno, who later updated his post to report more than 200 such malicious sites.

Vulnerability monitoring firm Secunia added a new IE flaw to its website today, this one caused by an error in .HTA applications. The flaw allows execution of an .HTA application on the user's system without user interaction, according to Secunia.

Integrated threat management firm Sophos echoed Microsoft's advice to practice web surfing in the absence of a patch.

"With no patches yet available to plug this hole, both home users and businesses need to exercise caution here," said Carole Theriault, senior security consultant at Sophos. "Users without any additional security measures, such as firewall and anti-virus software, and users who surf the web and open emails without care, are at much higher risk than those who practice safe computing."

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
anotherearlyfrommicrosoftpatchsecurity

Partner Content

Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
Alienated from your own data? You’re not alone
Promoted Content Alienated from your own data? You’re not alone
5 essential digital transformation ideas
Promoted Content 5 essential digital transformation ideas
Top 5 Benefits of Managed IT Services
Promoted Content Top 5 Benefits of Managed IT Services

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • 11th Annual Fraud Prevention Summit 2022
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Frank Washkuch
Mar 27 2006
10:49PM
0 Comments

Related Articles

  • Intel memory firmware bug hits hundreds of products
  • Aruba publishes patches for 21 security bugs
  • Atlassian patches auth bypass in Seraph
  • VMware admins asked to patch eight vulnerabilities
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NSW digital driver's licences 'easily forgeable'

NSW digital driver's licences 'easily forgeable'

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

Kmart Australia re-platforms ecommerce site to AWS

Kmart Australia re-platforms ecommerce site to AWS

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co sizes up six-figure customer exodus a year to fixed wireless

Digital Nation

CTO Juergen Mueller offers a glimpse into SAP's metaverse play
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
COVER STORY: A Year in the Metaverse
COVER STORY: A Year in the Metaverse
COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: Data and IoT set digital agriculture on a sustainable future
Why do DeFi and DAOs matter to business?
Why do DeFi and DAOs matter to business?
Lendlease launches its own metaverse in Milan
Lendlease launches its own metaverse in Milan
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.