Print | Send on Yahoo! | PDF version | Feed RSS | Filed Under: MISCELLANEOUS

Microsoft Short On Change

Date: 12/10/2008
Author: Razvan Stoica

Patch Wednesday Skips Critical IE vulnerability

As Microsoft's December patch rolls by , nicely bedecked with updates for security flaws that have plagued computers for the past few weeks, the astute observer might note the conspicious absence of a patch for a new flaw in the way Internet Explorer 7 parses XML that can lead to total compromise of affected systems.

Exploit code for this flaw exists in the wild in the form of malicious JavaScript on (mostly) chinese malware-spreading websites. The flaw was published by Chinese IT security outfit Knownsec.

http://www.scanw.com/blog/archives/303

Non-chinese-reading readers are advised to use the google-translated version we've provided a link to here.

http://translate.google.com/translate?hl=en&u=http%3A%2F%2Fwww.scanw.com%2Fblog%2Farchives%2F303&sl=zh-CN&tl=en

The exploit is used to download and execute a known Trojan, so most AV users are relatively safe for the moment. However, the minute the payload is changed, the picture will become completely different. Remains to be seen if Microsoft will issue an out-of-cycle patch or wait for the usual month before acknowledging and fixing the issue.


Share our story:
DiggStumbleUpondel.icio.usYahooMyWebFurlGoogle

Comment on this:
Name:
Email:
Your email address will not be published!

Please enter the code from the image below.
The code is not case sensitive
Verification Image
Reload image
 
 
Calendar
March 2010
MoTuWeThFrSaSu
1234567
891011121314
15161718192021
22232425262728
293031    
« Feb March Apr »
Tag Claud
conficker message messages computer security infected trojan pharmacy windows bitdefender word downadup virus microsoft software canadian files file online worm twitter omelette review rogue exploit antivirus spam data system malware