By exploiting the zero-day bug, hackers could either get Internet Explorer to run malicious code remotely, or crash the browser. Microsoft has promised a fix.
For the second time in two days, Microsoft Corp. on Wednesday acknowledged a zero-day bug in Internet Explorer, but this time promised to patch the problem.
"We have confirmed this vulnerability," wrote Lennart Wistrand, lead security program manager, on the Microsoft Security Response Center (MSRC) blog. "I am writing a Microsoft Security Advisory on this…but we wanted to make sure customers knew we were aware of this and we will address it in a security update."
Secunia tagged the vulnerability with its second-most-dire "highly critical" label.
Although IE 7 and January edition of the IE 7 Beta 2 Preview are vulnerable to attack, Microsoft's Wistrand said that the March 20 version of IE 7's preview is not. TechWeb confirmed that the current IE 7 Beta 2 Preview, available for downloadhere, is safe, by independent testing using the proof-of-concept code that has been posted publicly.
Microsoft touts IE 7 as substantially more secure from attack than earlier versions; last month, in fact, Gary Schare, director of product management for IE, said that the final edition of 7 would "put an end to the last bastion of drive-by downloads."
Scripting vulnerabilities have plagued IE for more than two years. The most recent was a November 2005 flaw that was used by a large number of spyware sites to secretly install software on users' PCs
How Enterprises Are Attacking the IT Security EnterpriseTo learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Infographic: The State of DevOps in 2017Is DevOps helping organizations reduce costs and time-to-market for software releases? What's getting in the way of DevOps adoption? Find out in this InformationWeek and Interop ITX infographic on the state of DevOps in 2017.
Digital Transformation Myths & TruthsTransformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.