Microsoft to release emergency Internet Explorer patch on Monday

The patch will fix a vulnerability in Internet Explorer 6, 7 and 8

Microsoft will release a patch on Monday for older versions of its Internet Explorer browser, deviating from its normal repair schedule due to the seriousness of the problem.

The vulnerability, which is present in IE 6, 7 and 8, is a memory corruption issue. It can be exploited by an attacker via a drive-by download, a term for loading a website with attack code that delivers malware to a victim's computer if the person merely visits the website.

Microsoft released a quick fix for the issue earlier this month, but did not have a more permanent patch ready when it released its monthly batch of patches last Tuesday. The company will occasionally release an emergency patch if the software vulnerability is considered a high risk.

"While we have still seen only a limited number of customers affected by the issue, the potential exists that more customers could be affected in the future," wrote Dustin Childs, group manager for the company's Trustworthy Computing Group, on a company blog on Sunday.

The patch, which will be released at 10 AM PST, will be distributed through Windows Update. Childs wrote users will not have to uninstall the quick fix before applying the patch, which will be installed automatically for those who have automatic updates enabled.

Security vendor Symantec credited a group called Elderwood as finding the IE vulnerability due to similarities in the attack code that uses the vulnerability with other attack code.

The Elderwood group has discovered as many as nine other vulnerabilities since 2009 and appears to favor targeting defense contractors, human rights groups, non-governmental organizations and IT service providers, according to a Symantec report issued in September.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

2014 ARN Women in ICT Awards - Nominate Now!: Nominations have opened for WIICTA 2014 and will stay open until October 22. But don't be late, be among the first in and NOMINATE NOW!!!

Tags securityMicrosoftpatch managementdata protectionExploits / vulnerabilitiesmalware

More about MicrosoftSymantec

ARN Directory | Distributors relevant to this article

ARN Directory | Vendors relevant to this article

Comments

Comments are now closed

 

Latest News

01:38PM
Google Nexus 9 pre-sales start at $479
12:56PM
Xero: Larking about, Kiwi style...
11:39AM
World's most powerful life sciences supercomputing facility to stay in Victoria
11:18AM
Nextgen Networks appoints former AAPT exec as new MD
More News
21 Oct
NewLease & Red Hat Breakfast Briefing (Melbourne)
21 Oct
DCIM Solutions Architect
22 Oct
NewLease & Microsoft Technical Sessions
23 Oct
NewLease & Red Hat Breakfast Briefing (Sydney)
View all events