Follow Us

Microsoft finally produces Explorer iFrame patch

A month later than needed.

Microsoft has finally produced a patch for the security hole in Internet Explorer that has become widely exploited in the past month.

The hole in iFrame Explorer tags was released publicly in October before Microsoft was informed, putting the software giant on the back foot immediately. Since then, several successful attempts have been made by hackers to exploit the hole. Most dramatically, an advertising company was hacked last week and banner ads on a large number of European websites inadvertently infected visitors.

The patch has been released outside of Microsoft's usual monthly security cycle - demonstrating its urgency. The vulnerability, MS04-040, allows attackers to take complete control of a compromised system and can be exploited by getting users to visit websites where malicious code is downloaded.

"We are aware of some proof-of-concept code and public attacks" that take advantage of the flaw, said Stephen Toulouse, security program manager at Microsoft's security response center. It is urging users to apply the latest patch as soon as possible, he added. The flaw doesn't affect users who have already installed XP SP2, however.

Meanwhile, Microsoft reissued three of its fixes from October for users of SP1 who may not have been offered the updates earlier. The problem involves SP1 users who may have downloaded the SP2 patch but have not installed it on their computers yet.

Microsoft's Windows Update and Automatic Updates service wouldn't have offered the October fixes automatically to such users, Toulouse said.







Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *