Microsoft’s emergency patch for IE
December 22, 2008
The threat led Microsoft to mobilize security engineering teams worldwide to deliver a software cure “in the unprecedented time of eight days.”
According to researchers at software security firm Trend Micro, attacks based on the vulnerability in the world’s most popular Web browser were spreading “like wildfire” with millions of computers already compromised.
Microsoft typically releases patches for its software on the second Tuesday of each month and rushing this fix to computer users out-of-cycle is testimony to the severe danger of the threat, according to Trend Micro.
“People should run, not walk, to get it installed,” said Trend Micro advanced threat researcher Paul Ferguson. “This vulnerability is being actively exploited by cyber-criminals and getting worse every day.”
The IE software patch will be automatically applied to hundreds of millions of personal computers due to standard update settings in the machines, according to Microsoft Security Response Alliance director Mike Reavey.
Wednesday morning, business networks using IE began getting the critical fix through routine patching processes.
Reavey said Microsoft went into “emergency response” mode on December 9 after it first learned of the attacks on IE browsers.
A day later, Microsoft published a security advisory that “listed workarounds that blocked all known attacks.”
“Over the course of the next eight days, this advisory was updated five times, adding newer workarounds and mitigations,” Reavey said. “We also continually monitored the threat environment, noting when the attacks began to change in nature and scope.”
Source: The Daily Star
Comments
Got something to say?
You must be logged in to post a comment.


