You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft to patch patch for IE

'Critical' fix in the wings...

Tags: internet explorer, ie, microsoft, patch

By Robert Lemos

Published: 7 October 2003 06:38 GMT

Microsoft will release a cumulative patch for Internet Explorer at the weekend, plugging a security hole that had been used by Trojan horse program QHosts to compromise consumers' PCs.

The patch - the fortieth that Microsoft has issued this year - seals several security holes in Internet Explorer 5.01, 5.5 and 6.0 for all versions of Microsoft Windows. The giant deemed the patch critical to all versions of Windows, except Windows Server 2003, which runs with more security in its default installation.

The patch repairs a previous patch that didn't properly protect against two ‘object type’ vulnerabilities. The vulnerabilities have been exploited by Trojan horse QHosts to compromise people's PCs when they browse a website that has attack code built in.

"An attacker could seek to exploit this vulnerability by hosting a specially constructed web page," Microsoft stated in the advisory. "If the user visited this web page, Internet Explorer could fail and could allow arbitrary code to execute."

That's exactly what happened at FortuneCity.com, when an unknown attacker was able to replace a banner ad on the site with code that copied the QHosts program to any computer that viewed the page with Internet Explorer. The program doesn't attempt to spread itself, so it isn't considered a computer worm or a virus.

Microsoft has been sued by a Los Angeles resident for its handling of security patches and for allegedly putting customers at risk by not offering proper security for its Windows operating system.

Robert Lemos writes for CNET News.com.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
Technical Analyst - SMS, SCCM, WSUS - Patch & Release

The role will involve the assessment of vulnerabilities, patch testing and application deployment via remote systems such as SMS/SCCM, WSUS and ...

Information Technology Engineer

Troubleshoot problems in commonly used operating systems (Windows XP, Vista, Windows 7) and other applications (Microsoft Office Suite, Exchange ...

Information Security Analyst - ISO27001, IT Systems compliance

You will also be responsible for building, configuring and deploying network hardware and applications, re-cabling, desk moves, management reporting ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: