Welcome Guest. | Log In| Register | Membership Benefits
Dark Reading's CSIsland Weblog
Topics:   SophosLabs Insights

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share

Emergency Microsoft Internet Explorer Patch Arrives Thursday


Posted by Graham Cluley, Jan 20, 2010 01:28 PM

The IT world sighed with relief at the news that Microsoft is releasing an out-of-band patch for Internet Explorer on Thursday, Jan. 21.

In a security advisory posted on its Website, Microsoft announced the emergency patch will not only address attacks that are targeting Internet Explorer 6 users, but it will also fix the vulnerability in versions 7 and 8 of the popular Web browser.

That's not just news for Internet Explorer users, of course. It's also positive news for the folks at Microsoft, who must have been smarting to learn rivals Firefox and Opera have seen an increase in downloads since European governments advised users to switch browsers.

I was always a bit wary of that advice, anyway. Many firms have found it hard enough to switch from the (now somewhat creaky) Internet Explorer version 6 to the latest edition, let alone deal with the possible complications that could arise when you change to another browser that your users might not be familiar with and that might not work with some of your Web applications.

It's good news for those of us who aren't working for one of the 30-odd companies targeted by Chinese hackers, too, since we are beginning to see other cybercriminals exploiting the flaw and placing it on copycat Websites in the hope of infecting unsuspecting users.

As you can see in the following video, it's really not hard to take advantage of the Internet Explorer exploit:

Microsoft should be praised for its rapid response to a critical situation. It couldn't have been easy for its team to produce the patch so quickly after news of the "Operation Aurora" hack attack broke. The Internet will be a little bit safer once everyone rolls out the patch.

Graham Cluley is senior technology consultant at Sophos, and has been working in the computer security field since the early 1990s. When he's not updating his award-winning blog on the Sophos website, you can find him on Twitter at @gcluley. Special to Dark Reading.

« What Data Discovery Tools Really Do | Main | User Security After The Google Hack »



Sign up now for the weekly InformationWeek Blog Newsletter.


This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




Related Content

Sponsored by:
sponsor logo
Seven for 7: Best practices for implementing Windows 7
Windows 7 is here to stay. Discover how to enhance your overall enterprise security by taking advantage of its new powerful endpoint security features.


Sophos Security Threat Report: 2010
SophosLabs received 50,000 new malware samples every day in 2009. Malware attacks are broadening and becoming more evasive with social networking sites and new computing platforms becoming primary targets for hackers. Read the 2009 security threats trends and learn how to protect yourself in 2010.

How To Protect Your Critical Information Easily
Safeguarding massive amounts of sensitive, confidential data--from legally protected personal information to intellectual property and trade secrets--from malicious attacks and accidental loss is one of IT's biggest challenges. With employees having greater mobility than ever before to work outside the office, the job of protecting data has never been more difficult.