Microsoft Internet Explorer users, beware. There’s a security flaw in all versions of the browser that leaves you wide open for attack. At least two million computers have already been infected.
The exploit doesn’t require users to click on links or download software from the Internet. Rather, it infects users when they open a Web page. The goal is to steal passwords, according to security experts, gain access to financial data and otherwise steal the victim’s identity.
“Microsoft is continuing its investigation of public reports of attacks against a new vulnerability in Internet Explorer,” said the company in a release on its Web site. Microsoft did not offer information on when a patch might be available.
Unpatched and Dangerous
Security flaws in browsers are certainly nothing new. But the difference with this one is there is no patch. No fix from Microsoft means that millions of Internet users may be at risk of infection simply from browsing the Web, according to Graham Cluley, a senior security consultant at Sophos.
“We are seeing infections on pornographic Web sites — and it’s not clear if these have been hacked or have been deliberately set up to infect surfers,” Cluley said. “Of course, Web-site attackers don’t just target porn sites. We see something like 20,000 new infected Web pages every single day — that’s one every 4.5 seconds — and the vast majority of those are legitimate sites that have been compromised by the likes of an SQL injection attack.”
How to Protect Yourself
Some computer users may be tempted to switch, if only temporarily, to alternative browsers such as Firefox, Safari and Google Chrome. Even Microsoft has suggested this as a temporary workaround.
However, Cluley cautions that all browsers have vulnerabilities and can be exploited — and switching the browser all employees use in a corporate setting isn’t a practical…