Patch Tuesday Followed Immediately By New Exploit Wednesday
Not even a moment after Microsoft fixed 28 vulnerabilities in their software this past Patch Tuesday, a brand new exploit popped up in Internet Explorer 7.
The new exploit allows attackers the ability to execute arbitrary code whenever someone visits a malicious website. Currently only users running Windows XP and Server 2003 are being targeted, so you Vista users haven’t a thing to worry about. Microsoft said they’re currently working on a patch to fix the issue, but they were unable to set a date.
“Internet Explorer remote code execution vulnerabilities have very high impacts since the source of the malicious payload can be across any site on the Internet,” said eEye's director of Research and Preview Services, Andre Protas. “An even more critical problem is generated when clients are administrators on their local hosts, which would run the malicious payload with Administrator credentials.”
Until this issue is taken care of, those of you that are using IE7 can go and snag eEye’s Blink Software for protection from this threat. Or, you could go snag one of the other browsers, such as Mozilla’s Firefox or Google’s Chrome. I hear they’re not too shabby!
Image Credit: Microsoft