On The Insider: Celebs in Miami for the Super Bowl
BNET Business Network:
BNET
TechRepublic
ZDNet

By Ina Fried
Posted on ZDNet News: Jul 30, 2004 7:18:00 PM

Microsoft on Friday released a patch for Internet Explorer designed to close three critical holes in the browser, including one that paved the way for the Download.Ject Trojan horse.

The software maker offered a work-around earlier this month and had promised in recent days that a comprehensive fix would be coming soon. Microsoft has also worked with law enforcement to shut down the Russian server that had been the source of malicious code.

The new patch, which is available from Microsoft's security Web site, closes the hole, and Microsoft encouraged all IE users to update their browsers. Technically, the flaw is what's known as a cross-domain vulnerability, through which an attacker is able to cross a security boundary within the browser to deliver and execute malicious code.

Microsoft security program manager Stephen Toulouse said that the company was already working on an Internet Explorer update when it became aware in late June that the vulnerability was being exploited. "Once we became aware of the specific attack on our customers, that's when we began to mobilize," Toulouse said, pointing to the company's work with law enforcement and Internet service providers.

The patch also addresses two other publicly known flaws in IE, both related to image processing and both rated as critical because they could allow malicious code to be run on a vulnerable system.

Toulouse said the company does not know of any attacks related to these two flaws, but he added, "We want to make sure that customers have this update so they are protected."

Security company Symantec encouraged Web surfers to apply the patch.

"With the widespread use of Microsoft Internet Explorer in both the enterprise and consumer environments, it is critical that security patches be applied immediately," Alfred Huger, senior director of Symantec Security Response, said in a statement.

Some have said that IE vulnerabilities have become so common that Web surfers should consider other browsers.

Toulouse noted that the company has improved IE in the forthcoming Windows XP Service Pack 2, adding that those running that version of the operating system were not vulnerable to the attack because of changes the company made to the internal structure of the browser.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 62 Talkback(s)
summary
I think the short version of it really is that they had to find the Indi programmer who put those backdoors in and offer him enough money to tell them what he did and fix it (while putting in more backdoors).... (Read the rest)
Posted by: Outside T. Box Posted on: 08/01/04 You are currently: a Guest | | Terms of Use
Too little too late  Bill_gates_Is_SATAN | 07/30/04
That may be but still patch IE  voska | 07/30/04
Good Point.  Outside T. Box | 08/01/04
IE?  Protostar | 07/30/04
certainly none........  pj-xmesh | 07/30/04
stupid icon clickers  NonZealot | 07/30/04
I had a dream.  bjbrock | 07/30/04
Sure man  pj-xmesh | 07/30/04
How do you find your files?  voska | 07/30/04
File manager  Loverock Davidson | 07/30/04
There is only one true file browser  NonZealot | 07/30/04
Use  Linux User 147560 | 07/30/04
I don't use dead programs. . .  CobraA1 | 07/30/04
2xExplorer  Loverock Davidson | 07/30/04
The best shell integration for Wn boxes  pj-xmesh | 07/31/04
The best shell integration for Wn boxes  Loverock Davidson | 07/31/04
Unfortunate, but true  CobraA1 | 07/30/04
Micro$loppy is just terrible  NonZealot | 07/30/04
I think you're pulling our leg happy (NT)  Martin Marvinski | 07/30/04
Perceptive Marvin  Don Bradley | 07/30/04
You said it!  KOS-MOS | 07/30/04
You're kidding, right? (NT)  Martin Marvinski | 07/30/04
This was better than Mike Cox  voska | 07/30/04
Mike Cox  Loverock Davidson | 07/30/04
you think so?  ryusen | 07/30/04
Hang tough, Mikey. These guys are just...  bjbrock | 07/30/04
Excellent Post! (NT)  Outside T. Box | 08/01/04
patches  yagijd | 07/30/04
Take comunion and you will be saved  NonZealot | 07/30/04
Umm  KOS-MOS | 07/30/04
How many people will fix these flaws?  Anton Philidor | 07/30/04
how about sharks with lasers on their heads(NT)  Monkey_MCSE | 07/30/04
Earning a Nobel with 8 words.  Anton Philidor | 07/30/04
Microsoft patches three critical browser flaws  Loverock Davidson | 07/30/04
mmmm - Still proving your ignorance eh!!  Iain_Peters | 07/30/04
Nope  Loverock Davidson | 07/30/04
Ignorance must be bliss for you...  php_developer | 07/30/04
your igorance ..  Iain_Peters | 07/30/04
I'm not elitist or anything  NonZealot | 07/30/04
Me neither  Loverock Davidson | 07/30/04
i guess that apt-get upgrade is out of the question?  Monkey_MCSE | 07/30/04
I was going to lambast you ...  Judas I. | 07/30/04
Yast2  Linux User 147560 | 07/30/04
SuSE updated for me  CobraA1 | 07/30/04
Well done, well done...  Mike Cox | 07/30/04
Perfect timing!  IT_User | 07/30/04
Evil M$  NonZealot | 07/30/04
Mike Cox kids around, but you got Bill G pegged right!  Xunil_Sierutuf | 07/30/04
Mikey my kids wish you were their Dad and my ex wants to have your baby  Squawkbox | 07/30/04
While still succuming to last months exploits.  Outside T. Box | 08/01/04
Microsoft heroics.  bjbrock | 07/30/04
Don't look now, but "NZ" and "MC"...  bjbrock | 07/30/04
(NT) When will ZDNET publish NEW info? This is the same OLD news.  Plain Logic | 07/30/04
IE & Windows  chiliboots2000@... | 07/30/04
One word for you....  hi and stuff | 07/30/04
3 more patched (hopefully) today  michael-t | 07/30/04
Installing patch changed my default browser to IE!!!  pfingerman | 07/30/04
RE:Installing patch changed my default browser to IE!!!  nite_w0lf | 07/30/04
Didn't here.  PA-ITGuy | 07/31/04
no kidding 2 little 2 late  mrjeremypjones | 07/30/04
Patch not released until it's exploited?!  CobraA1 | 07/30/04
summary  Outside T. Box | 08/01/04

What do you think?