internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Security Task Manager

Most Popular Software Downloads
Windows 7
Adobe Flash Player
AVG Anti-Virus Free
QuickTime for Windows
Mozilla Firefox 3
Windows Vista Service Pack 2 (Vista SP2)
Internet Explorer 8
Ad-Aware Free
Google Chrome
Winamp

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Official Windows 7 Beta Build Leaks to BitTorrent
A Year of Change Ahead for Microsoft in 2009


Software Reviews

Latest IE Zero Day Has XML Designs
Patch for New Zero-Day Exploit May Not Arrive Until Oct
Sean Michael Kerner

Security researchers are alleging that a zero-day exploit for Microsoft's Internet Explorer is in the wild.

The vulnerability stems from a buffer overflow condition in IE for an XML component called Vector Markup Language (VML). VML handles vector images that are specified via XML inside of an HTML page.

According to Verisign's iDefense Labs division, attackers are using the vulnerability as an attack vector to download Trojans or other arbitrary code on users' PCs.

According to Ken Dunham, director of Rapid Response Team at iDefense, fully patched Internet Explorer browsers are vulnerable to the VML buffer overflow condition, and exploits are in the wild.

Dunham noted that the attack is easily reproduced and has widespread attack potential in the near term.

Until a patch from Microsoft becomes available, Dunham advises that IE users disable JavaScript.

"Microsoft has now confirmed that it is aware of the vulnerability and the fact that exploit code is in the wild," a company spokesperson told internetnews.com.

A security update is now being finalized through testing to ensure quality and application compatibility and is on schedule to be released as part of the October security updates on October 10, 2006, or sooner as warranted.

For now, Microsoft has published a Security Advisory, which details steps customers can take to protect themselves against attempts to exploit the vulnerability.

In its evaluation of the virus, Symantec (Quote, Chart) suggested disabling JavaScript in IE or using another browser. A security update that will address the vulnerability is currently being prepared by Microsoft, but it's not currently expected until Oct. 10th.

Andy Patrizio contributed to this story.

News courtesy of internetnews.com

September 19, 2006

Download Internet Explorer Security Patches Now!Download

View All Microsoft Service & Security Releases

Contents:
1. Patch for New Zero-Day Exploit May Not Arrive Until Oct


Additional Articles:

  • Malware Hacker Attack Linked to Spammers
  • Malware Attack Thwarted, But Danger Lurks
  • US Gov: Beware of IE
  • Microsoft Issues Security Update for Trojan
  • Another IE Flaw in the Wild?
  • Microsoft Faces Angry IE Users' Questions
  • Microsoft Releases New Tool to Zap Download.Ject
  • Microsoft: Out-of-Cycle Security Patch Coming
  • 'Critical' IE Patch Released
  • MS Patch Barrage Comes with IE Fix
  • 'Drag-and-Drop' IE Flaw Persists
  • MS Patches IFRAME Vulnerability Out of Cycle
  • Microsoft Patches Three Holes, Offers Removal Tool
  • Microsoft Patch Day Plugs 3
  • Microsoft Patches 3 Critical Flaws
  • IE Workarounds for New Zero Day Exploit
  • Unpatched IE Flaw Now Exploitable
  • Microsoft Going Critical on Tuesday
  • Microsoft Crafts Critical Patches
  • Microsoft Warns on Windows, IE Flaws
  • Microsoft Patches IE, Windows, Office
  • Microsoft's Patch of a Patch Will Be Late
  • IE Vulnerability Spreads to Email
  • IE VML Exploit Growing in Severity
  • VML Exploit Patched, Questions Remain
  • PowerPoint, IE Hit by New Zero-Day Flaws