facebook rss twitter

Critical Internet Explorer patch in MS security update

by Steven Williamson on 15 February 2012, 13:25

Tags: Microsoft (NASDAQ:MSFT)

Quick Link: HEXUS.net/qabcof

Add to My Vault: x

Please log in to view Printer Friendly Layout

A Microsoft security update this week delivers four critical patches, including the repair of an Internet Explorer vulnerability that could allow attackers to gain user rights to your computer.

Security update MS12-010, is said to resolve four privately reported vulnerabilities in Internet Explorer.

“The most severe vulnerabilities could allow remote code execution if a user views a specially crafted web page using Internet Explorer,” reads the bulletin. "An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the logged-on user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.”

The security update applies to Internet Explorer 7, Internet Explorer 8, and Internet Explorer 9.

"The Internet Explorer bulletin should be considered a top priority, as there is a risk of code execution attacks," warned Jim Walter, manager of McAfee's threat intelligence service.

"If not attended to, browser exploits can be particularly harmful."

Vulnerabilities in Windows Kernel-Mode drivers, C Run-Time Library .NET framework, and Silverlight have also been exposed as critical.

All four critical updates refer to a code that could allow remote code execution on a client system if a user views a specially crafted web page

Overall there are nine patches correcting a total of 21 vulnerabilities in this week’s update.

For more details check out the Microsoft bulletin.



HEXUS Forums :: 2 Comments

Login with Forum Account

Don't have an account? Register today!
MS never does IE any favours
Deleted
MS never does IE any favours

Yeah, I know what you mean. I too wish they'd just leave it open.