PC Support, Server Support, Microsoft Office, Outlook, Windows, Server, Site visit, Remote Support, VPN, Email, Broadband, IT, Anti-Virus, Slow Computer, Computer Repair
IT Outsourcing, IT Department, IT Support Contracts, IT Technical Help, IT Helpdesk, IT Solutions, IT Systems, IT Professionals, Outsourced IT Management, IT Assessments, IT Project Deployment, Web Design, Email and Domain Hosting and Registration, PC Network Installation, IT Network Support, Remote IT Support, Remote Data Backup, Windows Software Support, Windows Server Support
Home  |  About  |  Services  |  Testimonials  |  FAQs  |  IT Glossary  |  Links  |  Contact  |  Press Section
You are here:   Home   >>   Press Articles
      
Microsoft patches 10 critical IE bugs
Microsoft today shipped 2010's second rush update for Internet Explorer (IE), patching 10 vulnerabilities -- including one hackers have been exploiting for weeks.

That bug had been reported to Microsoft by a Beijing security company in mid-November, 2009, Microsoft confirmed, months before news broke that it was being used by attackers. In fact, Microsoft wrapped up work on the fix for IE6 by Feb. 26, according to date stamps on the affected file.

The update, tagged MS10-018, was released two weeks early because Microsoft had tracked a growing number of attacks against IE6 and IE7. The bug has been used by malicious sites to launch drive-by attacks for much of the month.

The last emergency IE update was issued January 21 to fix eight flaws, including one that had been exploited to attack Google, Adobe and scores of other companies. Google blamed China for the attacks, a move that led to its decision to relocate its Chinese-language search engine to Hong Kong.

All 10 vulnerabilities patched in today's update -- which was originally slated for release April 13, the next regularly-scheduled Patch Tuesday -- were rated "critical," the highest level threat in Microsoft's four-step scoring system. But there were clear differences in the risk profiles of different versions of IE.

IE6, the 2001 browser that many want to see dead and buried, was affected by eight of the 10 bugs, with seven of those eight marked critical. IE7, which debuted in 2006 prior to the release of Windows Vista, contained seven out of the possible 10, with five vulnerabilities tagged critical. IE8, on the other hand, was touched by just three of the 10, with only two critical.

"The message today should be to get onto IE8," said Andrew Storms, director of security operations at nCircle Network Security. "Not just ditch IE6, but dump IE6 and IE7."

For the most part, Storms saw the 10 vulnerabilities as "pretty typical IE bugs. Except for [CVE-2010-0806], none of them are particularly troublesome, or no more than we've come to expect." CVE-2010-0806 is the Common Vulnerabilities & Exposure ID for the vulnerability that prompted the rush, or "out-of-band," update.

And that vulnerability received most of the attention today from Storms and other researchers, including HD Moore, the creator of the Metasploit framework and chief security officer at security company Rapid7, which manages the open-source Metasploit project.

According to Moore, Microsoft's out-of-band hand was forced when a Taiwanese researcher nicknamed "Nanika" revamped public exploit code so that it worked reliably against not only IE6, but also the newer IE7. "Before, Microsoft said, 'Not that big a deal,' but then the facts changed and they say, 'Sorry, this does affect IE7 reliably.' They changed their mind."

When Microsoft first warned customers of the memory corruption flaw in the "iepeers.dll" file, it said that attacks were aimed only at IE6 users, and that Protected Mode in IE7 would help protect users of that version. Protected Mode is a pseudo-sandbox that tries to keep attack code from escaping the browser to modify, add or delete data elsewhere on the PC.

Microsoft said nothing of that protection today, and rated the vulnerability as critical for both IE6 and IE7.

The bug had been reported to Microsoft by ADLab of VenusTech, a Chinese security firm based in Beijing, in mid-November 2009, Microsoft said today. "The vulnerability was responsibly reported to Microsoft & prior to active attacks surfacing in March 2010," said Jerry Bryant, a senior manager with the Microsoft Security Response Center (MSRC), in an e-mail. "We confirmed that it was exploitable on November 30. At that time, we continued to investigate the issue to identify the root cause, develop the update and enter into our extensive testing cycle."

According to the date stamps on the iepeers.dll files for the various browsers, Microsoft had completed the fix -- and passed it on to internal testing -- no later than Feb. 26 for IE6 and March 12 for IE7.

As Microsoft said both today and earlier, the iepeers.dll vulnerability does not affect IE8.

"I'm not surprised that Microsoft released the update," said Moore. "Working exploit code has consistently accelerated Microsoft's update process." As late as yesterday, other researchers had expressed surprise that Microsoft was able to craft a fix so quickly. "They focus on IE bugs more than anything else, because they are so high profile," said Moore.

"And Microsoft can actually fix things pretty quickly, within a week or two or three," he continued. "They generally address [bugs] quickly, but then hold off until its widely exploited. Otherwise, they wait until the next release."

MS10-018 can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services.
      
IT Support Dublin, IT Services Dublin, Computer Support Services Dublin
        
        
Courtesy of www.computerworld.com
        
        
        
Techsure Ltd : Unit 232, Blanchardstown Corporate Park 2, Dublin 15, Ireland
Telephone: 01 8249049Fax: 01 8249050Email:info@techsure.ie
powered by:go2web
Services
        
IT Support, Computer Support, Tech Support, IT Support Contracts, Computer HelpdeskIT Support
Outsourced IT Support OutsourcingOutsourced Management
IT Audit, Network Assessment, Tech CheckIT Assessments
Project Roll Out CountrywideProject Deployment
Computer Contract IT SupportIT Support Contracts
Email, Website, Domain Registration, Domain Hosting, SEO Search Engine OptimisationInternet related
Instant IT Support Immediate Connection through our remote connection software, remote controlQuickbooks
      
      
      
Press Archive
      
        
MS Windows News
      
Windows 7 ShutdownMicrosoft remains mum on Windows 8 upgrades from Vista, XP [Apr '12]
Windows 7 ShutdownOutlook continually prompting for username and password [Feb '11]
Windows 7 ShutdownMicrosoft patches critical Outlook drive-by bug [Nov '10]
Windows 7 ShutdownMalware targets Windows USB [Jul '10]
Windows 7 ShutdownNew Microsoft support service offers XP users Windows 7 goodies[Apr '10]
Windows 7 ShutdownMicrosoft Patch Update[Apr '10]
Windows 7 ShutdownMicrosoft ending support for Itanium [Apr '10]
Windows 7 ShutdownMicrosoft patches 10 critical IE bugs [Apr '10]
Windows 7 ShutdownMicrosoft lowers Windows licensing costs for virtual desktops [Mar '10]
Windows 7 ShutdownMicrosoft again pushes patch linked to Windows blue screens [Feb '10]
Windows 7 ShutdownMinor updates only for Windows 7 SP1
      
IT Security News
      
Search engine optimization 'poisoning' way up this year: report [Nov '10]
Survey: Corporate PCs cluttered with malware [May '10]
10 obscure antivirus tools worth checking out [Apr '10]
BitDefender update wipes out Windows PCs [Mar '10]
Microsoft races to plug IE hole after exploit code released
      
General Tech Articles
      
Google's Sergey Brin: Facebook and Apple a threat to Internet freedom [Apr 12]
Five tips for speeding up Windows XP performance
Top 20 Windows 7 Shortcuts
EU invests €15.7 million cloud storage research project [Nov '10]
10 QuickBooks issues and how to resolve them [Jul '10]
'Why Firefox?' and 'Why Windows?' -- same answer? [Feb '10]
      
Business Tech News
      
IT Services DublinFive things you should know about BlackBerry Enterprise Server Express [Apr '10]
IT Services DublinDesktop computers will soon be 'irrelevant', says Google [Mar '10]
IT Services DublineBay conman gets four years [Mar '10]
IT Support DublinCarl Icahn selling off Yahoo shares
[Feb '10]
Business Computer Support DublinSilicon Valley faces rough road to recovery [Feb '10]