Friday, January 22, 2010

CRITICAL: Emergency Updates Released to Patch Serious Flaws in Internet Explorer

Microsoft has released a security bulletin describing eight new vulnerabilities discovered in Internet Explorer (IE) running on all current versions of Windows. An attacker entices users to a malicious web page and then uses the vulnerability in IE to execute code on the user’s computer, potentially gaining complete control over it. Additionally, it has been publicly reported that one of the vulnerabilities allowed hackers based in China to breach the networks of Google and many other technology companies including Adobe. More information on these breaches can be found on WatchGuard’s website.

It’s becoming more common for attackers to hijack legitimate web pages and infest them with malicious code. Once attackers entice users to these legitimate but booby-trapped web pages, they are able to use these flaws in IE to gain control of a victim’s machine.

Because these flaws create such a threat to a large number of Windows users, Microsoft has released emergency patches to fix them. These patches will be tested and applied automatically on the networks of 3D clients receiving patching services. All other users should immediately download and install the appropriate IE patches. These patches can be found in Microsoft Security Bulletin MS10-002 - Critical.

To find out more about the network security solutions (i.e. patching services) 3D can provide your business, visit our website at http://www.3dcorp.us/, email us at info@3dcorp.us, or call us at (360) 671-4906.

References: WatchGuard's LiveSecurity Service Update "Out-of-Cycle Cumulative IE Update Patches Google Hack Flaw,” WatchGuard Wire article “Hackers in China rumored to have hacked Google with IE zero day,” Microsoft Security Bulletin MS10-002 - Critical

0 comments:

Post a Comment