Advertisement
Promo

Security threats Toolkit

Story: Microsoft: Hole exploit threatens all IE versions

  • Previous comment

Posted by: lumension (Thursday 18 December 2008, 7:46 PM)

  • Reply

IE IE OH!

This is the second time in 18 months that Microsoft has gone out of band to release an emergency patch (last time being October for the RPC issue) for the Internet Explorer, which is being actively exploited right now. There has been Proof of Concept (POC) code for the exploit available since December 11th. Coming just the week before christmas and given the wide use of IE within business enterprises and severity of the vulnerability, clearly IT professionals need to patch this vulnerability as soon as business conditions permit. There were over 100 websites on the Dec 11th hosting some type of malware associated with this vulnerability. Today, that has grown to thousands of sites now hosting the malware.

Microsoft felt this issue warranted an out of band patch due to the underlying exploit being actively used in the wild and damage was mounting. Their are reports of up to 6000 compromised web sites hosting web pages that take advantage of the vulnerability.

A recent study titled “Understanding the Web browser Threat: Examination of Vulnerable Online Web browser Populations and the Insecurity Iceberg" found that 57% of IE users were not running the most current version that’s patched. This will be a wake up call to IT professionals to make sure to patch their browsers. This speaks volumes to the underlying problem with web-borne malware. We as a community are constantly trying to outsmart the bad guys on their delivery method. However, it is not necessarily a delivery / obfuscation issue – the underlying issue is a failure to patch, including their browsers. A recent Verizon study showed that over 70% the exploits used in web-borne malware had vendor patches available for up to a year and less then 1% had patches available within a 30 day window. The web-borne malware issue is a patch management issue and can be simply fixed by patching in a timely fashion according to industry best practices.

Private message disabled

lumension

lumension
LONDON, UK
Member since: October 2008

Site Activity Rating:

3

 


  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters