Feeds

Unofficial IE patch saves humanity

Third party, fire and theft

Beginner's guide to SSL certificates

Security researchers have released a patch designed to protect users against an outstanding Internet Explorer vulnerability in the absence of available security updates from Microsoft.

A new ad-hoc group of security pros, called the Zeroday Emergency Response Team (ZERT), has released an unofficial fix designed to address the Vector Markup Language (VML) component vulnerability in IE, the most serious of two unpatched IE vulnerabilities. It plans to release other security bug fixes in future.

Hackers are taking advantage of this VML security flaw in IE to infect users visiting pornographic websites. Opening maliciously constructed emails in Outlook is also a potential risk, especially as attacks targeting the vulnerability are growing in prevalence since their first appearance last week.

The security bug is unrelated to a (still unpatched) flaw in Microsoft's Direct Animation Path (daxctle.ocx) ActiveX control discovered earlier this month.

ZERT said users should replace its fix with Microsoft's patch once this becomes available. "It is always a good idea to wait for a vendor-supplied patch and apply it as soon as possible, but there will be times when an ad-hoc group such as ours can release a working patch before a vendor can release their solution," it said.

Separately, security management firm PatchLink released a more limited workaround designed to help its customers (and only its customers) protect their networks from the VML exploit.

PatchLink estimates the number of vulnerabilities in various applications released this year will reach 6,700, some of which will become the subject of exploit before vendors get around to releasing patches.

Because of the growing issue of unpatched (so called zero-day) exploits, IT administrators can expect to see more third party patches such as the VML patch released by the ZERT group. PatchLink advises to check the provenance of patches and carry out testing before applying fixes in case they cause more problems than they solve in a user's environment. ®

Internet Security Threat Report 2014

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.