Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

Microsoft Issues Super Patch for Serious IE Flaws

Software giant warns of six security holes in most recent versions of IE; says all users need cumulative patch immediately.

Joris Evers, IDG News Service

  • 0 Yes
  • 0 No

Microsoft late Thursday issued a cumulative patch for its Internet Explorer Web browser that also fixes six new vulnerabilities, the most serious of which could enable an attacker to take control over a user's system, the software giant says.

All currently-supported versions of Internet Explorer, 5.01, 5.5, and 6.0, are affected, putting tens of millions of Internet users at risk. Internet Explorer is the world's most popular Web browser.

In a security bulletin posted on its Web site, Microsoft urges all users to immediately apply the patch.

Versions of Internet Explorer that are no longer supported could also be vulnerable, Microsoft notes.

Previous Patches

A cumulative patch is a patch that includes all previously released fixes for a software product. The six newly-patched vulnerabilities exist in various parts of Internet Explorer and mainly put client systems at risk, but Microsoft deems the super patch "critical" for Internet and Intranet servers too.

Three of the six new flaws enable an attacker to run code on a user's system, while other vulnerabilities could be exploited to read files on a user's computer, trick the user into downloading malicious code or run script on the user's system, Microsoft says.

In addition to fixing the vulnerabilities, the patch package also permanently disables two vulnerable ActiveX controls, one linked to the MSN chat application and one to a feature for terminal services sessions, Microsoft says. ActiveX controls are small programs designed to perform a single task.

  • Recommend this story?
  • 0 Yes
    0 No

Dell's December Days of Deals

Featured APC Accessories

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC Smart-UPS Loaded with cutting-edge features, unique battery life predictor, unbeatable on-line efficiencies and software agents allowing remote UPS monitoring. Get 10% off your entire kart purchase!

People who read this also read:

  • 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
  • A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.

Sponsored Links