Microsoft has issued an emergency patch to fix a critical Internet Explorer vulnerability that puts users at risk. At least two million computers have been infected in the past week, most of them in Asia.
The out-of-cycle patch is available through Microsoft’s normal update options, including Windows Server Update Services, Microsoft Update, and Windows Update.
The fact that Microsoft broke its normal patch cycle is an indication of the importance of this patch, according to Wolfgang Kandek, CTO of Qualys.
“This is a critical flaw in the most widely used browser on the planet. Internet Explorer users have been exposed for at least a week to high risk while browsing the Internet,” Kandek said. “This risk includes having their computer falling under the control of outside attackers, which can then search the computer for personal information such as SSN, install key loggers that record log-in passwords to banking sites, and also use the computer for their own money-making activities.”
A Lightning-Fast Fix
The browser flaw was disclosed about a week ago, as a zero-day vulnerability and active exploits have been around the Internet for about that long. The exploit doesn’t require users to click on links or download software from the Internet. Rather, it infects users when they open a Web page. Microsoft offered several workarounds while it was working on a fix.
“The workarounds provided by Microsoft were very technical and quite cumbersome to implement, making it imperative for Microsoft to release a fix as quickly as possible,” Kandek said. One of the workarounds, however, wasn’t cumbersome — but it was a competitive downside. Microsoft, as well as many security analysts, recommended browsers stop using Internet Explorer until a fix was available.
“Given the typical requirements for developing, testing and packaging the changes to a program as widely deployed as Internet Explorer, we have seen one…