By Glenn Chapman
Agence France-Presse
SAN FRANCISCO -- Microsoft on Wednesday released an emergency patch to fix a pe
rilous software flaw allowing hackers to hijack Internet Explorer browsers and
take over computers.
The US software giant said security update MS08-078 addresses a vulnerability c
yber-criminals can exploit to their advantage.
"Microsoft encourages all IE customers to test and deploy this update as soon a
s possible," said Microsoft security response communications head Christopher B
udd.
The threat led Microsoft to mobilize security engineering teams worldwide to de
liver a software cure "in the unprecedented time of eight days."
According to researchers at software security firm Trend Micro, atta
cks based on the vulnerability in the world's most popular Web browser were spr
eading "like wildfire" with millions of computers already compromised.
Microsoft typically releases patches for its software on the second Tuesday of
each month and rushing this fix to computer users out-of-cycle is testimony to
the severe danger of the threat, according to Trend Micro.
"People should run, not walk, to get it installed," said Trend Micro advanced t
hreat researcher Paul Ferguson. "This vulnerability is being actively exploited
by cyber-criminals and getting worse every day."
The IE software patch will be automatically applied to hundreds of millions of
personal computers due to standard update settings in the machines, according t
o Microsoft Security Response Alliance director Mike Reavey.
Wednesday morning, business networks using IE began getting the critical fix th
rough routine patching processes.
Reavey said Microsoft went into "emergency response" mode on December 9 after i
t first learned of the attacks on IE browsers.
A day later, Microsoft published a security advisory that "listed workarounds t
hat blocked all known attacks."
"Over the course of the next eight days, this advisory was updated five times,
adding newer workarounds and mitigations," Reavey said. "We also continually mo
nitored the threat environment, noting when the attacks began to change in natu
re and scope."
Trend Micro has identified about 10,000 websites that have been infected with m
alicious software that can be surreptitiously slipped into visitors' unprotecte
d IE browsers to take advantage of the flaw.
A major Internet portal in Taiwan is among the legitimate websites unknowingly
tainted with malicious software aimed at IE's weak spot, according to Ferguson.
Hackers can take control of infected computers, steal data, redirect browsers t
o dubious websites, and use machines for devious activities such as attacks on
other networks, according to security specialists.
"What makes this so insidious is it takes advantage of a big gaping hole of IE,
which has the largest install base of any browser on the market," Ferguson sai
d.
IE is used on nearly three-quarters of the world's computers, according to indu
stry statistics from November.
Reavey said the patch consists of more than 300 distinct updates for more than
half-a-dozen versions of IE in scores of languages.
Analyst Rob Enderle of Enderle Group in Silicon Valley said it was "amazing" th
at Microsoft was able to turn out a complex critical fix in a week when such jo
bs typically can take a month or longer of intense work.
"Even with that, the release Emergency Response process isn't over," Reavey sai
d. "There is additional support to customers and additional refinement of our p
roduct development efforts."
Trend Micro urges IE users to heed precautionary advice from Microsoft, or avoi
d using the browsers, until the patches are applied.
The "exploit" is similar to one used recently to steal user names, passwords an
d other information from people playing online games in China, according to Tre
nd Micro.
(UPDATE) Microsoft releases patch for Internet Explorer flaw
No TrackBacks
TrackBack URL: http://blogs.inquirer.net/cgi/mt/mt-tb.cgi/10915
6 Comments
Categories
- AMD (1)
- APC battery pack (3)
- Accenture (2)
- Acer (2)
- Adobe (1)
- Advertising (1)
- Amazon (1)
- Apple (8)
- Appliances (1)
- Asus (6)
- Axioo (1)
- Barack Obama (1)
- Bebo (1)
- Blackberry (2)
- Blue (1)
- Broadcasting (3)
- Bugs (1)
- Call Centers (2)
- Canon (2)
- Causes (3)
- Celebrities (4)
- Cisco (1)
- CommunicAsia 2007 (10)
- CommunicAsia 2008 (1)
- Computerization (2)
- Computex 2007 (4)
- Convergence (2)
- Convergys (1)
- Creative (1)
- Crime (1)
- Customer Service (1)
- Cybercafes (1)
- DAVE Networks (1)
- Dell (1)
- Digital Cameras (1)
- E-mail (2)
- EMC (1)
- Education (3)
- Elections (2)
- Environment (5)
- Ericsson (1)
- Events (11)
- Gadgets (60)
- Going Green (1)
- Google (8)
- Graphics Cards (1)
- HDTV (3)
- HP (5)
- HTC (6)
- Hacking (2)
- Hard Disks (2)
- Hardware (33)
- IBM (1)
- INQUIRER.net (1)
- IPTV (3)
- Innovations (1)
- Intel (10)
- Intel Developer Forum (3)
- Interactive TV (1)
- Internet (34)
- Joost (1)
- LCD (4)
- LED TV (1)
- LG (1)
- Laptops (16)
- Larry Ellison (1)
- Mac mini (1)
- MacBook (1)
- Magic Mouse (1)
- McAfee (1)
- Microsoft (12)
- Mobile (44)
- MobileTV (1)
- Motorola (4)
- Music (8)
- NBC (1)
- Neo (1)
- Nokia Connect 2007 (3)
- Offbeat (2)
- Olympus (2)
- Ondoy (1)
- Oracle (1)
- Oracle World (1)
- Outsourcing (1)
- Overclocking (1)
- PDAs (2)
- Philips (3)
- Plasma TV (1)
- Plurk (1)
- Printers (1)
- Red Fox (3)
- Reviews (18)
- Robots (6)
- Samsung (2)
- Scott McNealy (1)
- Seagate (1)
- Security (7)
- Sennheiser (1)
- Social Networking (8)
- Software (9)
- Sony (3)
- Sony Ericsson (5)
- Speakers (2)
- Students (2)
- Sub-notebooks (1)
- Sun Microsystems (1)
- Tech Support (2)
- Telepresence (1)
- Television (1)
- Terabyte drives (1)
- Twitter (2)
- UAV (2)
- UMPC (2)
- UPS (1)
- Uncategorized (14)
- Videos (57)
- Viruses (2)
- Voice (1)
- WeRoam (1)
- Western Digital (1)
- Wifi (2)
- Windows 7 (1)
- Yahoo! (5)
- YouTube (8)
- Zune (3)
- demo (1)
- digital content (1)
- e-Services Philippines 2008 (2)
- iMac (1)
- iPhone (2)
- iPod (2)
- iiView (1)
- lifestyle (1)
- multifunction TV (1)
- netbooks (1)
- smartphone (1)
- sound business (2)
- touch-screen (1)
- washing machines (1)
Monthly Archives
- January 2011 (2)
- December 2010 (7)
- November 2010 (13)
- October 2010 (6)
- December 2009 (2)
- November 2009 (2)
- October 2009 (3)
- September 2009 (2)
- August 2009 (1)
- July 2009 (1)
- April 2009 (2)
- March 2009 (3)
- February 2009 (8)
- January 2009 (11)
- December 2008 (7)
- November 2008 (8)
- October 2008 (10)
- September 2008 (12)
- August 2008 (13)
- July 2008 (7)
- June 2008 (5)
- May 2008 (6)
- April 2008 (15)
- March 2008 (2)
- February 2008 (3)
- January 2008 (3)
- December 2007 (2)
- November 2007 (7)
- October 2007 (14)
- September 2007 (17)
- August 2007 (8)
- July 2007 (8)
- June 2007 (28)
- May 2007 (1)
Pages
Search
About this Entry
This page contains a single entry by published on December 17, 2008 5:17 PM.
REVIEW: Motorola ZN200 and W388 was the previous entry in this blog.
DTI website defaced is the next entry in this blog.
Find recent content on the main index or look in the archives to find all content.

For a quick shortcut as to where to download the patch, here's the microsoft li
nk:
http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx
For users of XP SP2, here's the actual download link:
http://www.microsoft.com/downloads/details.aspx?familyid=0190a289-164e-41a7-8c0
1-fa1aaed3f531
We use FF at home but my grandma still uses IE. I guess we still need the patch
.
Just use Google CHROME. Problem solved.
This is one of the many reasons why I have switched to firefox a long long time
ago.
Microsoft typically releases patches for its software on the second Tuesday of each month and rushing this fix to computer users out-of-cycle is testimony to the severe danger of the threat, according to Trend Micro. "People should run, not walk, to get it installed," said Trend Micro advanced t hreat researcher Paul Ferguson. "This vulnerability is being actively exploited by cyber-criminals and getting worse every day." The IE software patch will be automatically applied to hundreds of millions of personal computers due to standard update settings in the machines, according t o Microsoft Security Response Alliance director Mike Reavey.
Best regards, Alex, CEO of youtube converter
Wednesday morning, business networks using IE began getting the critical fix th rough routine patching processes.
Best regards, Katya, CEO of dvd to dvd burner, iscsi initiator vista