SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Hackers target unpatched IE bug

Hackers target unpatched IE bug

By:  Robert McMillan  On: 01 Dec 2005 For: IDG News Service (San Francisco Bureau) Creator

Microsoft Corp. is warning Internet Explorer users to be careful where they browse because attackers are now targeting a critical unpatched bug in the software. If successful, these attackers could possibly use this bug to seize control of a user's system, Microsoft says.

That response didn't sit well with one security expert. "This issue is a damning one for Microsoft's commitment to security," said Russ Cooper, editor of the NTBugtraq newslist and a scientist with security vendor Cybertrust Inc., speaking via instant message. "They have known about the module which contained the flaw since May this year. At the very least, that module should have been fixed even if not released to the public."

"The result is that we are taught, yet again, that if you want to get a vendor's attention to a flaw in their product you need to create an exploit and publish it," he said. "Just telling them is not sufficient."

Microsoft's security advisory criticizes Computer Terrorism for doing just that. "Microsoft is concerned that this new report of a vulnerability in Internet Explorer was not disclosed responsibly, potentially putting computer users at risk," the advisory states. "We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests."

Security vendor Sophos PLC has not yet seen attackers exploiting this code, said Sophos Senior Technology Consultant Graham Cluley. This suggests that Microsoft may wait until its next scheduled security update on Dec. 13 to fix the problem, rather than rushing out a patch immediately, he said. "If someone has just posted something up on few Web sites, then they probably wouldn't bother. But if there is something actively spreading, then they probably would do it," he said. "I think they're probably loathe to issue an update out of the cycle."










Sign up for our Newsletters












Print |  Views: 729   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Robert McMillan Robert McMillan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.
blog comments powered by Disqus