Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > PC Technology Zone > Windows Operating Systems and Software » Microsoft to issue out-of-cycle patch for the 'unknown exploit'
Closed Thread
Old 12-16-2008, 11:19 PM   #1 (permalink)
Mak213's Avatar
 

Join Date: Sep 2004

Location: C:\Windows\System32

Posts: 25,661

Mak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to all

Default Microsoft to issue out-of-cycle patch for the 'unknown exploit'

We're not even really sure if the reports of new exploits affecting Internet Explorer browsers are actually valid, but in case they are, Microsoft will issue a patch that addresses the problem those exploits may be targeting.

It's the kind of development that could give "zero-day" a whole new meaning: a wave of alleged Internet Explorer exploits, the total number of experimentally validated cases of which apparently numbers zero. Still, the subject matter is of some concern: the apparent ability of an ActiveX control -- for the dozens upon dozens of sites that still use them -- to leave code in memory after cleanup that's still capable of being executed without privilege.

Rather than take a chance on all these reports being false, Microsoft is taking the step of patching the Web browser anyway, categorizing the issue as Critical. Tomorrow morning at 10:00 am Pacific Time, 1:00 pm Eastern Time, Microsoft will issue an out-of-cycle patch that addresses the likelihood of the problem. The patch will apply to all versions of Internet Explorer ranging back to IE5.01 Service Pack 4, all the way to IE8 Beta 2; for all versions of the operating system dating back to Windows 2000 SP4.

The good news out of all of this is that the possibility of an exploit has apparently made Microsoft aware of a legitimate problem, or at least something that could become problematic.

A blog post from Microsoft's security vulnerability team today describes the problem in the greatest level of detail we've seen thus far: "Malicious HTML that targets this vulnerability causes IE to create an array of data binding objects, release one of them, and later reference it. This class of vulnerability is exploitable by preparing heap memory with attacker-controlled data ('heap spray') before the invalid pointer dereference."

Source
__________________
R.I.P. Danny L. Trotter
14 Nov 1945 - 4 Sept 2009
Images created by CarnageX | Decaptured...Listen! | Visit Baezware!! | You've been Mak'd! | 儿做好
I do not accept support questions via EMail, PM, IM or my Spaces page! .:|:. This is what happens when an unstoppable force meets an immovable object.
Thanks to all the guys on the staff for your support in my time of need. Hefe you are my personal Hero for your contribution.



<<<< If I help you, or you just like what I said, rep me
Mak213 is offline  
Old 12-17-2008, 06:11 AM   #2 (permalink)
Saxon's Avatar
 

Join Date: Feb 2007

Posts: 6,362

Saxon is just really niceSaxon is just really niceSaxon is just really niceSaxon is just really nice

Default Re: Microsoft to issue out-of-cycle patch for the 'unknown exploit'

This zero day was worrying, on the exploit sites that I trawl through I have seen this supposed exploit show up for download or even for sale but I haven't had the chance to see if it works.

If the zero day in question was unpatched I can only picture the shear level of havoc this would have caused.
__________________
I am not here for long I am deploying soon so please don't expect anything long winded.

Saxon is offline  
Old 12-17-2008, 12:23 PM   #3 (permalink)
 
Hard Core Techie

Join Date: Nov 2004

Posts: 11,642

EricB will become famous soon enough

Default Re: Microsoft to issue out-of-cycle patch for the 'unknown exploit'

they need to kill activex
__________________
The Ultimate Hard Drive Utility PowerMax 4.23. (It now has the ability to clean a Boot Sector virus on the quick erase option.)
The best browser Netscape 8
Have you accidently delete something? Look here (trial. the better one) and here(free)
EricB is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Crysis 1.2 patch dario03 PC Gaming 34 08-29-2008 02:42 AM
Please Analyse, ethernet controller no longer working...[P] djmaddogfreak HijackThis Logs (finished) 16 07-04-2008 10:05 PM
Seeminly Unsolveable Problem! Reply ASAP! yoshi1476 Windows Operating Systems and Software 44 06-13-2008 12:48 AM
2nd HijackThis Log File xXxexpertxXx HijackThis Logs (finished) 30 03-10-2008 06:24 AM
HELP: Infected System script.kiddie Virus - Spyware Protection / Detection 6 12-15-2007 01:54 PM