comScore
Uncategorized Tuesday, September 18th 2012 at 8:40 am

Internet Explorer Flaw Big Enough for Microsoft to Issue Warning

Microsoft isn’t one to readily admit that they’re dealing with a major security flaw, in that they’re not going to publicize the fact. To be fair, most technology companies aren’t often the ones that come forward with potential exploits. Someone, or some group, usually has to first do some damage before these loopholes get closed with any speed. A major exploit that works across operating systems? Well, that’s another story. Microsoft has already responded to the latest critical exploit found in Internet Explorer 6, 7, 8, and 9, but the help provided might not do much.

This is the issue according to the security advisory released by Microsoft:

A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.

That doesn’t really address the biggest concern with this exploit, however. According to Ars Technica, Internet Explorer was exploited using this particular maneuver on Windows XP, Windows Vista, and Windows 7. A vulnerability being used like this across multiple browser versions and operating systems is rare, but could cause major issues.

Microsoft’s recommended course of action? Download the Enhanced Mitigation Experience Toolkit. Our recommendation? Avoid the whole possibility by using a different browser.

(Microsoft via Ars Technica, image via Simon Bisson)

Relevant to your interests

Filed Under |
  • http://twitter.com/iAmTheQG QG

    ha ha, microsoft products ahve a tendency of screwing the users over… i quit windows after the ME farce, lol… Chrome is the answer

  • http://www.facebook.com/people/Bruce-E-Screws-Jr/5200506 Bruce E. Screws Jr.

    There a patch that will work instantly that was developed by a third party. It even future proofs against some other security concerns. It is called the “Google Chrome Patch.” It is much more effective.

  • Firefox

    Chrome is maleware and spyware its self. I recommend Firefox.

  • Anonymous

    Firefox FTW!!!!!!!!!!!!!!!!

  • as

    have is true . (ahve)

  • Idlethoughts

    Safari never seem to give me much trouble.

  • Asreal

    I would agree, but Chrome tends to report what you do back to Google. Plus Firefox is a bloated bag of shite; everytime I want to use it, it tells me to wait while the damn thing updates itself… Might have to bite the bullet and go for Safari…