Welcome | Sign In
CRMBuyer.com
Security

Microsoft's Slow Reflexes Prompt Outside Firms to Fix IE Flaw

Print Version
E-Mail Article
Reprints
Microsoft's Slow Reflexes Prompt Outside Firms to Fix IE Flaw

A lot of damage can occur prior to Microsoft's April 11 target for issuing a patch, said Scott Carpenter, director of Secure Elements. It is likely that Microsoft will work hard to speed up its release, he suggested, especially as two other firms have already offered their own fixes.


A new flaw in Microsoft's (Nasdaq: MSFT) Internet Explorer has come to light, but the software giant does not expect to issue a patch for it until April 11. However, at least two outside firms have issued patches that may be used in the interim.

The Microsoft vulnerability exploits the way Internet Explorer handles HTML code objects, according to Sandeep Dhameja, senior security consultant at SpiderLabs, the forensics and penetration testing division of AmbironTrustWave.

The flaw affects fully patched Windows XP SP2 computer systems running both Internet Explorer version 6.0 and the latest version 7 Beta 2 (January 2006 edition) browser applications, Dhameja told TechNewsWorld.

"The exploit code for this vulnerability is available on the Internet, and it allows hackers to commandeer vulnerable computers by tricking Web surfers to visit Web sites containing malicious code," he said. "Once such a site is visited, malicious code will attempt to infect the computer system with keystroke loggers -- backdoor applications [that] not only attempt to steal payment card information but also online banking information including debit card transaction data."

200 and Counting

There are some 200 Web sites already infected with the malicious code that exploits the IE vulnerability, Scott Carpenter, director of the Secure Elements security labs, told TechNewsWorld.

"There have been reports that a developer [for a major enterprise resource planning vendor] had his password stolen after visiting on the sites," he said.

A lot of damage can occur prior to Microsoft's April 11 target for issuing a patch, Carpenter pointed out. It is likely that Microsoft will work hard to speed up its release, he suggested, especially as two other firms have already offered their own fixes.

"I am not sure Microsoft can handle the bad press of having a non-Microsoft patch -- two of them -- out there," he remarked.

Microsoft is proposing a temporary workaround by having users disable their active scripts setting within the Internet Explorer browser.

This "answer" places the burden on the users, though, Carpenter said. "What we have now is a browser that is vulnerable to malware, so Microsoft wants users to disable most of it and follow safe browsing practices until it releases its patch."

Two Patches

Then there are the patches two Internet security firms have released. They are not designed as permanent solutions, Dave Mason, host of the nationally syndicated ComputerTalk radio show and technology consultant, told TechNewsWorld.

"I generally don't recommend third-party patches. Microsoft has enough trouble getting it right; third parties should be viewed very skeptically. I would recommend waiting for the Microsoft patch," he urged.

That may seem like sound advice -- unless, of course, your password to an ERP vendor's development site has been stolen.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Ballmer Gives Shareholders - and Dell - Cause for Optimism
November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning
November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Salesforce.com Pumps Up Volume of Workplace Chatter
November 19, 2009
Salesforce.com has developed a collaboration platform that puts social networking to work. Salesforce Chatter facilitates employee collaboration on projects through Facebook-like profiles, status updates, feeds and groups. The question remains whether employees will be as open to social networking in the workplace as they are in their personal lives.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network