You are here: silicon.com > Software > Malware

Malware

Microsoft patches three "critical" IE security holes

Urges everyone to go on an update frenzy…

By Ina Fried

Published: 2 August 2004 08:40 GMT

Microsoft has released a patch for Internet Explorer designed to close three critical holes in the browser, including one that paved the way for the Download.Ject Trojan horse.

The software giant offered a work-around earlier this month and had promised in recent days that a comprehensive fix would be coming soon. Microsoft has also worked with law enforcement to shut down the Russian server that had been the source of malicious code.

The new patch, which is available from Microsoft's security website, closes the hole and Microsoft encouraged all IE users to update their browsers. Technically, the flaw is what's known as a cross-domain vulnerability, through which an attacker is able to cross a security boundary within the browser to deliver and execute malicious code.

Microsoft security program manager Stephen Toulouse said that the company was already working on an IE update when it became aware in late June that the vulnerability was being exploited. "Once we became aware of the specific attack on our customers, that's when we began to mobilise," Toulouse said, pointing to the company's work with law enforcement and ISPs.

The patch also addresses two other publicly known flaws in IE, both related to image processing and both rated as critical because they could allow malicious code to be run on a vulnerable system.

Toulouse said the company does not know of any attacks related to these two flaws, but he said: "We want to make sure that customers have this update so they are protected."

Security company Symantec urged web surfers to apply the patch.

"With the widespread use of Microsoft IE in both the enterprise and consumer environments, it is critical that security patches be applied immediately," Alfred Huger, senior director of Symantec Security Response, said in a statement.

Some have said that IE vulnerabilities have become so common that web surfers should consider other browsers.

Toulouse noted that the company has improved IE in the forthcoming Windows XP Service Pack 2, adding that those running that version of the operating system were not vulnerable to the attack because of changes the company made to the internal structure of the browser.

Ina Fried writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
PHP Developer, Online Design Agency, Basingstoke - 35k - 40k

Excellent internet skills in using various browsers and search engines Knowledge of browser quirks and variations PHP Developer, Online Design ...

Front End Development / JavaScript / 40k / City of London

Ideally you will have experience with the following: - DHTML (3 years) - JavaScript (3 years) - CSS (3 years) - Cross Browser Development (3 years) ...

Security Manager (SOC Manager), SC Security Cleared

Basic awareness of computer based vulnerability analysis testing. Moderate awareness of computer based vulnerability analysis testing. Basic ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: