On mySimon: Issey Miyake Automatic Watch for Men
BNET Business Network:
BNET
TechRepublic
ZDNet

December 17th, 2008

Microsoft's incredible IE patch turnaround

Posted by Ryan Naraine @ 12:38 pm

Categories: Arbitrary Code Execution, Browsers, Data theft, Exploit code, Malware, Microsoft, Patch Watch, Pen testing, Responsible disclosure, Viruses and Worms, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Microsoft Internet Explorer, Microsoft Corp., Web Browsers, Patches, Security, Internet, Ryan Naraine

Guest post by Eric Schultze

Apply IE emergency update now, don’t ask questions — Eric SchultzeMicrosoft’s latest Internet Explorer out-of-band patch release needs to be installed right away.  The number of infected websites is growing at an alarming rate — even people visiting legitimate websites are getting hacked with this exploit.

Patch it now - just do it.  Why did this come out as an emergency release?

[ SEE: As attacks escalate, MS readies emergency IE patch ]

It  looks like Microsoft was informed of the IE zero day at the same time as everyone else – namely, last Tuesday (Patch Tuesday).  Based on Microsoft MSRC blog posts, starting on Tuesday, Microsoft studied the exploit and reviewed source code and determined that it impacted all versions of IE.   From that point on, it can be assumed that Microsoft has been working quickly on a patch for all versions of IE.

Microsoft had to determine how serious the issue was – as that gave them guidance as to whether or not to release an out of band patch or wait until the next monthly cycle.  By late last week, Microsoft was aware that this issue was starting to infect user’s systems at a faster rate than they’ve seen with past zero day exploits.  Specifically, attackers were loading the exploit on legitimate websites so that even users who visit only non-nefarious websites might also get infected.  Based on this level of data, it’s my belief that Microsoft decided the issue warranted an out-of-band patch release.

[ SEE: Hackers exploiting (unpatched) IE 7 flaw to launch drive-by attacks ]

Researching, fixing, testing, and releasing a security patch within an eight day window is an incredible feat — especially given the need to support all versions of IE across all platforms and languages.  This is an ‘all hands on deck’ response from Microsoft – I don’t think we’ll see this as the norm for less critical patches in the future as it is quite disruptive to their own processes.

Now, it’s equally as important for customers to roll out this patch to all of their systems as soon as possible.

I’d bet you a cookie that many companies can’t get it rolled out as quickly as Microsoft got it built.

* Eric Schultze is chief technology officer at Shavlik Technologies, a vulnerability management company.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 43 Talkback(s)
Tell me about it!
Since we went to a completely managed and locked down desktop things have gotten worse. The guys who 'manage' our desktop have not even incorporated XP SP3 into the base build they are so bust chasing... (Read the rest)
Posted by: Oreamnos_americanus Posted on: 12/30/08 You are currently: a Guest | | Terms of Use
So much for the "sitting on it" theory.  ye | 12/17/08
One example does not disprove that  Michael Kelly | 12/17/08
It does when we're talking about this exploit.  ye | 12/17/08
You just know someone's going to mention...  Sleeper Service | 12/17/08
So what you're basically saying  frgough | 12/18/08
OMG WOW!! ONE PATCH!!! HOLY CRAP!!!!  itanalyst2@... | 12/17/08
You are still using XP??!!  LBiege | 12/17/08
You're using Vista voluntarily?  masonwheeler | 12/19/08
No surprise you have a reading comprehension problem.  ye | 12/17/08
Help me here  914four | 12/24/08
RE: Microsoft's incredible IE patch turnaround  CobraA1 | 12/18/08
"Should" be done?  justanitguy | 12/18/08
Yeah.  CobraA1 | 12/18/08
Sure.  Cayble | 12/22/08
Do you have a clue as to how complex this can be?  DevGuy_z | 12/18/08
I am a developer.  CobraA1 | 12/18/08
RE: I am a developer  Yensi717 | 12/18/08
Glad you're not on *my* team.  masonwheeler | 12/19/08
Remember...  914four | 12/24/08
You're caught  KTLA | 12/22/08
Care to elaborate?  914four | 12/24/08
Bad boys need more positive reinforcement than good boys  Michael Kelly | 12/18/08
I agree Michael  914four | 12/24/08
Sheesh guys  frgough | 12/18/08
Maybe a better solution...  bjbrock | 12/18/08
As if they should not hustle over this?  pikeman666@... | 12/18/08
Home More Secure Than Work  MichP | 12/18/08
Tell me about it!  Oreamnos_americanus | 12/30/08
RE: Microsoft's incredible IE patch turnaround  phatkat | 12/18/08
RE: Microsoft's incredible IE patch turnaround  NighTTripper | 12/18/08
And it was entirely coincidental...  gregoryk@... | 12/18/08
RE: Microsoft's incredible IE patch turnaround  claytonn | 12/19/08
This, that, there.  Mitch 74 | 12/20/08
MS vs Firefox  Beatnyama | 12/21/08
Vista flop?  Patanjali | 12/27/08
When a fix doesn't break anything...  jasonp@... | 12/22/08
Either situation can involve either method  Patanjali | 12/27/08
Practice makes perfect!!!  bbneo | 12/24/08
Since WHEN has M$ been so fast to respond? confused  btljooz | 12/24/08
Knowing the way...  914four | 12/24/08
Ye is a he?  Isocrates | 12/25/08
I stand corrected  914four | 12/26/08
Several years old and no exploit until now!  Patanjali | 12/27/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline