The Inquirer-Home

Microsoft patches a gaping security hole

Out-of-cycle again
Tue Mar 30 2010, 13:30

SOFTWARE INSECURITY SISYPHUS Microsoft has released an out-of-cycle patch for users lazy or ignorant enough to still be using an old version of Internet Explorer.

It's generally rare that threats are deemed serious enough for Microsoft to not wait until its next Patch Tuesday, which would be April 13th now, but a vulnerability hit Internet Explorer 6 and 7 that left them open to potential remote code execution.

Microsoft said, "The vulnerability exists due to an invalid pointer reference being used within Internet Explorer. It is possible under certain conditions for the invalid pointer to be accessed after an object is deleted."

Microsoft became aware of targeted attacks and has issued the emergency patch, recommending that users install the update as soon as possible.

Even Internet Explorer 8 users will need to apply this patch, because the company is including fixes for nine other vulnerabilities that likely would have waited until Patch Tuesday but instead will be fixed now.

It's just a fact of life now that all web browsers have to patch against the latest threat, and Microsoft, with a still dominant though shrinking market share, is of course the biggest target. µ

Share this:

Comments
Got the update for IE8 as well...

... so even those that have upgraded to IE8 got a patch.

posted by : Olle P, 31 March 2010 Complain about this comment
So all Windows 2000 users are lazy. Nice!

I would upgrade to IE 9 if I could. Bill Gates does not want that however. I would like to upgrade to a newer OS as well, but Microsoft includes spyware in there newer versions of Windows so I am not able to do that either.

posted by : Lazy Windows 2000 user, 30 March 2010 Complain about this comment
-=7=- Enterprise Extends trial thru rest of Year.

How many 'O RED'R Forgot todays Last Day. Well Now time to boner Up Again. Windows -=7=- ENTERPRISE Can be Downloaded & Installed thru End of Year. 64 bit or 32. Heres Story:

popular demand, the Windows Enterprise Trial program has been extended.” Interested parties now have until December 31, 2010 to download and evaluate the Windows 7 Enterprise trial version.

MJ States:The trial copy is a full working version of Windows 7 Enterprise that does not require a product key (it’s embedded inside the download). Users have 10 days from the time they sign up to activate the product. If they don’t activate, the system will shut down once an hour until activated, Which Won't Do, seems.. After the 90-day period ends, the system will shut down once an hour until a user either purchases Windows 7 (and performs a clean install of it, including drivers and applications, or removes it from their system. Kur Plunk. Mark Hours, Charge Ponies,Make Momees', Happy.

Windows 7 has impressed early adopters

After 31Dec'010, just cann't Install any more. So Install on Last Day,too., Use 90 Day Open 24/7 & Peep,peep,peeper. Then 1 hour max, for Rest of Life of Computer HDD. Wow, whatyamoore yevant.Well in 1 hour mode, cann't upDate Sucker,errr, mean Precious O/S software. Just keep adding & ading HDD, till infinity or New Years. Auld Lange Siene. How many Have Eye Crushed, About Half.

drashek

posted by : Entepenuear..., 30 March 2010 Complain about this comment
Remember kids!

Always properly deconstruct your objects!

posted by : Ken, 30 March 2010 Complain about this comment
Ignorant or lazy, not mutually exclusive.

Nor is "stuck" an excuse. You put yourself into the M$ strait-jacket and didn't protest when the arms were tied behind your back. Now you're too lazy to walk out even though the door to Linux is open.

I sympathize that you guys in IT are victims of idiots both above and below, but you need to direct your remarks to those idiots, and the ones at M$.

posted by : bigger_luddite, 30 March 2010 Complain about this comment
Wow

Ignorant or lazy... great way to get more readers.

Please see the raft of recent articles in far more reputable publications and blogs stating that most of the IE 6 usage left on the net being forced by corporate IT policies on business machines. IE6 was "it" for a reliable corporate standard long enough that a ton of cutom app programming was written for it. Until there is a compelling economic reason to go back and rewrite an expensive batch of core code (in a time where expensive projects just don't fly), then we will just have to live with it- and with the snarky comments from the peanut gallery

That's where many of us are. We're not "ignorant or lazy... or snarky and falsely superior, we're just stuck.

posted by : CorpIT, 30 March 2010 Complain about this comment
Ignorant or lazy!!!

Hey Asavin Wattanajantra, SCREW YOU!!!!!! I don't run IE8 because i am ignorant or lazy. I don't run it for the same reason Bob mentioned in a previous post, compatibility problems. Just because Microsoft releases a new version and says it is better doesn't mean it is. Only and Ignorant or Lazy person would make a snap judgment before considering the fact that there are legitimate reasons not to run something.

posted by : Brian, 30 March 2010 Complain about this comment
Ignorant or lazy?

I still use IE7 due to site compatability problems that still exist with IE8 even though there is a compatability button - it still has isues. This is my preference and I am not ignorant or lazy (Thanks for the snap judgement by the way!)Hopefully IE9 adresses this problem when it comes out and I'll install it. Until then, IE7 works just fine for me.

posted by : Bob, 30 March 2010 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

The Pirate Bay poll

Will UK ISPs blocking of The Pirate Bay stop you from using it?