internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Microsoft Set to Fix IE Zero Day Flaw
Out-of-Cycle Patch for IE Expected Wednesday
Sean Michael Kerner

Microsoft is set to release an out-of-cycle patch for the zero-day IE flaw that has left users at risk since Thursday December 11th when the flaw was first reported.

The patch is expected tomorrow and for many users, won't come too soon.

The flaw is rooted in IE's XML parser and affects all versions of IE. The flaw could allow an attacker to execute arbitrary code on a Windows PC. The attack vector used for exploiting the flaw has been primarily by way of infected Web sites that an IE user visits.

Microsoft expanded its advisory regarding the flaw last Friday, December 12th.

"At this time, we are aware only of attacks that attempt to use this vulnerability against Windows Internet Explorer 7," Christopher Budd, Microsoft security response communications lead, said in a statement e-mailed to InternetNews.com. "Microsoft encourages customers to test and deploy this update as soon as possible."

As of Saturday December 13th, Microsoft reported that roughly 0.2 percent of IE users worldwide may have visited Web sites that are exploiting the vulnerability.

"That percentage may seem low. However it still means that a significant number of users have been affected," Ziv Mador and Tareq Saade wrote on the Microsoft Threat Research and Response Blog. "The trend for now is going upwards: we saw an increase of over 50 percent in the number of reports today compared to yesterday."

Trend Micro Advanced Threats Researcher Ivan Macalintal estimated the number of infected sites to be at 6,000 as of Saturday and growing. The use of websites as a delivery mechanism for attack is one that has grown significantly in 2008. Cisco's 2008 annual security report found that exploited Web sites in 2008 were responsible for 87 percent of all web based threats

The Microsoft IE update will be delivered at 10 AM PT on Wednesday Dec 17th though the Microsoft Update site and will be pushed to Microsoft Update users via automatic updates.

The IE XML zero day flaw was missed in Microsoft's December Patch Tuesday update, which included four separate IE vulnerabilities. The next regularly scheduled Patch Tuesday update from Microsoft is not expected until January 9, 2009.

Out of cycle patches are uncommon, but not unheard of for Microsoft.

The company issued several out of cycle patches for IE over the years, including one for a URL spoofing flaw. 2004 also saw and out of cycle patch for an IFRAME (define) flaw that Microsoft had originally denied. would be fixed out of cycle.

News courtesy of internetnews.com

December 17, 2008

Download Internet Explorer Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. Out-of-Cycle Patch for IE Expected Wednesday


Additional Articles:

  • Internet Explorer 7: Ready for Public Consumption
  • Gates Mixes It Up with IE, Atlas
  • Microsoft Plans Patch for IE Hole
  • New IE Exploits Create Security Scramble
  • IE 7 Is 'Layout Complete'
  • IE7 Beta 2 Out of Preview
  • Microsoft to Take Third Shot at IE 7 Beta
  • IE, Firefox Users at Risk from New Flaws
  • Third IE 7 Beta Has Layout Changes
  • First Release Candidate for IE 7 Hits
  • Report: IE 7 Has the Best Anti-Phishing Filter
  • Microsoft Planning Life After IE7
  • IE 7 Is Out the Door
  • IE 7's First Security Hole
  • Another Bug Bites IE7
  • Is IE 7 Limiting Remote Access SSL-VPNs?
  • IE 7 Tops 100M Download Mark
  • Internet Explorer at Zero-Day Risk
  • Microsoft Issues IE Security Alert
  • Microsoft to Roll Back the Clock on ActiveX
  • Internet Explorer 8 Passes the 'Acid2' Test
  • Internet Explorer 8 Tries New Compatibility Solution
  • IE8 Beta Soon But Few Details Yet
  • Microsoft Admits IE Still Flawed
  • Microsoft Patches IE, But Security Issues Remain
  • Hackers Target IE 7 Browser Again
  • EU to Insist Windows Includes Rival Web Browsers


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs