Follow Us

Microsoft to patch flaw in Internet Explorer

Patch to fix flaw linked to Chinese hacker attack on Google

Microsoft will release an out-of-band patch - meaning a patch that breaks the standard Patch Tuesday release cycle - to address the Internet Explorer flaw at the heart of the attacks in China against Google and other targets.

George Stathakopoulos, general manager of the Microsoft Security Response Center (MSRC), stated: "We continue to see limited and targetted attacks against Internet Explorer 6 and encourage customers to upgrade to Internet Explorer 8. We also recommend customers consider deploying the workarounds and mitigations provided in Security Advisory 979352 until the security update is ready for broad distribution."

Andrew Storms, director of security operations for nCircle, commented on the unusual step of breaking the Patch Tuesday release cycle. "Given the never-ending lack of attention on the Microsoft IE bug, it was inevitable that [Microsoft] would release a patch on or before their regularly scheduled February release."

It is certainly true that there has been no shortage of media attention devoted to the targeted attacks in China, and the revelation that a zero-day vulnerability in Internet Explorer was apparently a prime attack vector. Germany and France have even added their two cents worth by recommending that everyone abandon IE - at least until a patch is available for the flaw.

The fact that the exploit code for the Internet Explorer vulnerability is now publicly available in-the-wild adds fuel to the fire. Storms points out that in the absence of the international attention on the attacks in China, this flaw probably wouldn't be updated out-of-band. "If the public vulnerability had not been tied to the Google breach announced last week, the bug would have been worrisome, but not nearly as epically perceived by many."

Dan Kaminsky, director of penetration testing for IOActive, offered his own cautious insight, "We know there is an exploit in the field that is causing some amount of damage using this exploit as its entry point, but this entire situation is defined more by what we don't know than what we do."

Kaminsky is alluding to the veiled and sparse information trickling out about the attacks. The Internet Explorer vulnerability has been confirmed as an attack vector, but there are hints and implications that there are others as well. Google has been identified as a target, along with as many as 30 other organizations--most of which haven't been identified.

The knee-jerk response to lay the blame at Microsoft's feet and scapegoat the Internet Explorer web browser misses the point and ignores the larger issue that, not only was this a sophisticated and targeted attack, but that a foreign government is accused of perpetrating the attacks and the United States State Department is backing those claims.

An attacker with dedication and resources can find a way to compromise just about any web browser or operating system. The impact of precision spearphishing attacks such as this, which use zero-day vulnerabilities to infiltrate systems and allow the attackers to extract information, is a much more serious security issue than whether or not Internet Explorer gets patched before 9 February (the next regularly-scheduled Patch Tuesday).

nCircle's Storms concurs "While the attacks were successful against many high profile companies, they are still of a limited and highly-targeted nature. For the mass majority of users, careful browsing practices coupled with up to date antivirus will provide significant risk mitigation."

Watch for more details on the timing of the emergency Internet Explorer patch tomorrow. Microsoft continues to investigate this situation, so customers can also look for the latest updates on the Microsoft Security Response Center (MSRC) blog.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Desktop modernisation

On the one hand, there is the need to keep the existing desktop environment efficient, secure...

Download Whitepaper

Top 10 myths about virtualising business-critical applications

Even though virtualization has brought positive change to enterprise IT over the last decade,...

Download Whitepaper

Aligning CFO and CIO priorities

Forward-thinking organisations are viewing cloud computing as an investment in business...

Download Whitepaper

The new corporate network

Businesses can’t afford to have employee productivity suffer because they cannot use their...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...
LogMeIn Rescue

Accelerate Your IT Efficiency

View the latest capacity management resources including whitepapers, videos and news.

Find out more...

Site Map

* *