On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

July 3rd, 2008

On deck from MS: Four 'important' patches but nothing for IE

Posted by Ryan Naraine @ 12:57 pm

Categories: Arbitrary Code Execution, Browsers, Data theft, Exploit code, Hackers, Malware, Microsoft, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Patch Management, Microsoft Internet Explorer, Microsoft Corp., Flaw, Web Browsers, Microsoft Windows, Security, Internet, Operating Systems, Software

4 ‘important’ patches but nothing for IENext Tuesday, Microsoft plans to ship four security updates for multiple flaws affecting Windows, Microsoft SQL Server and Microsoft Exchange Server but the absence of fixes for publicly known Internet Explorer issues is causing raised eyebrows among security professionals.

According to the company’s advance notice for July’s Patch Tuesday, all four bulletins will be rated “important,” meaning that these flaws could be exploited to result in compromise of the confidentiality, integrity, or availability of users data, or of the integrity or availability of processing resources.

All supported versions of Windows are affected by these bulletins, including the newest Windows Vista and Windows Server 2008 operating systems.

[ SEE: Exploit code released for unpatched IE 7 vulnerability ]

However, if you’re an Internet Explorer user, you can’t be happy that Microsoft is leaving you on hold for another month without a cumulative IE update.

There are several known — and publicly discussed — code execution flaws haunting the world’s most widely used browser.  These include the Safari-to-IE bug reported by Aviv Raff, the cross-domain zero-day affecting IE 6, the cross-site scripting bug reported by Roel Schouwenberg, the print table of links issue, and the serious iFrame hijacking flaw discussed by Sirdarckat.

There really is no excuse for the delay in patching the Safari-to-IE code execution flaw. It was reported to Microsoft since 2006!

* Image source: Jeff Wilcox’s Flickr photostream (Creative Commons 2.0).

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 17 Talkback(s)
I've used FF since 1.0 and before with beta releases.
When you upgrade to IE-7, you get a lot more than you bargained for. MS builds a a lot of extra "enhancements" into their browser upgrades. And yes, they are not liked by many. So, many choose not to... (Read the rest)
Posted by: joe.smetona@... Posted on: 07/12/08 You are currently: a Guest | | Terms of Use
Am I correct that uninstalling Safari mitigates the problem?  NonZealot | 07/03/08
You've got to be kidding.  Intellihence | 07/03/08
I'm sure getting rid of IE would mitigate the problem as well.  A Grain of Salt | 07/03/08
Agreed  NonZealot | 07/03/08
You know as well as I do...  A Grain of Salt | 07/03/08
No. Not at all  mdemuth | 07/03/08
No, you are not correct.  msalzberg | 07/04/08
RE: On deck from MS: Four 'important' patches but nothing for IE  Intellihence | 07/03/08
Jump in?  Confused by religion | 07/03/08
I didn't know the iPhone was around in '06. (nt).  A Grain of Salt | 07/03/08
Quicktime  laura.b | 07/08/08
Interesting Browser Fact  itanalyst2@... | 07/07/08
Better choices.  joe.smetona@... | 07/08/08
this proves only that Firefox users tend to be Geeks  tech_walker | 07/08/08
I've used FF since 1.0 and before with beta releases.  joe.smetona@... | 07/12/08
RE: On deck from MS: Four 'important' patches but nothing for IE  ralphb@... | 07/10/08
Common problem with Microsoft.  joe.smetona@... | 07/10/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and