NEWS Microsoft will release a cumulative patch for Internet Explorer at the weekend, plugging a security hole that had been used by Trojan horse program QHosts to compromise consumers' PCs. The patch - the fortieth that Microsoft has issued this year - seals several security holes in Internet Explorer 5.01, 5.5 and 6.0 for all versions of Microsoft Windows. The giant deemed the patch critical to all versions of Windows, except Windows Server 2003, which runs with more security in its default installation. The patch repairs a previous patch that didn't properly protect against two ‘object type’ vulnerabilities. The vulnerabilities have been exploited by Trojan horse QHosts to compromise people's PCs when they browse a website that has attack code built in. "An attacker could seek to exploit this vulnerability by hosting a specially constructed web page," Microsoft stated in the advisory. "If the user visited this web page, Internet Explorer could fail and could allow arbitrary code to execute." That's exactly what happened at FortuneCity.com, when an unknown attacker was able to replace a banner ad on the site with code that copied the QHosts program to any computer that viewed the page with Internet Explorer. The program doesn't attempt to spread itself, so it isn't considered a computer worm or a virus. Microsoft has been sued by a Los Angeles resident for its handling of security patches and for allegedly putting customers at risk by not offering proper security for its Windows operating system. Robert Lemos writes for CNET News.com.
Microsoft to patch patch for IE
'Critical' fix in the wings...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Why is encryption important?
Data protection has become a hot topic, but where is the real threat and what can you do to protect your business? How...
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters





Comments
There is 1 comment. Join the discussion
1. peter simonitsch
it just shows how such companies act. take any risk not following the simplest development roules within sotware development, spend not suficient time on reasonable testprocedures and criticise people hurt by the consequences. they should debugg MS software at their costs but certainly not publish it. its the same manner like the IP's act. they deploy any rubbish via their networks and servers but take no rebonsibilities for it. the user pays anyway the service and for the fee he gets spam, worms and troyans. there is no customer support-organisation taking sonsumers party against that business practices.