Microsoft released a rare out-of-band patch Thursday morning. The emergency patch fixes the Internet Explorer zero-day security vulnerability that hackers have used in several high-profile targeted attacks, including the recent Trojan.Hydraq cyberattacks waged against Google and other large U.S. companies.
As Microsoft previously noted, the vulnerability affects Internet Explorer 6, 7 and 8, which make up the bulk of the versions consumers use today. However, it said the only in-the-wild exploit code for this vulnerability detected so far impacts IE 6. Still, Microsoft isn’t taking any chances. Because of in-the-wild exploits and the amount of media and customer attention on this exploit, Microsoft decided it was in customers’ best interests to issue a patch before the next Patch Tuesday on Feb. 9.
“The most likely attack vector used in the incidents seen thus far is targeted e-mails containing legitimate-looking attachments or links to web sites sent to high-level employees,” said Joshua Talbot, security intelligence manager at Symantec Security Response. “When the attachment is opened, an exploit for the vulnerability springs into action and the computer becomes infected.”
Newer Versions Less Vulnerable
Microsoft also confirmed that all current versions of Internet Explorer contain a Data Execution Prevention (DEP) bypass vulnerability. If not bypassed, DEP can help in stopping the exploit code. Therefore, newer versions of Internet Explorer running on Windows Vista and Windows 7 are less vulnerable to an active exploit, according to Don Leatham, a senior director of Business Development at Lumension.
“These versions of Windows have Address Space Layout Randomization (ASLR) that provides an extra level of protection beyond DEP,” Leatham said. “This is a clear, real-world example of the superior security model implemented in Windows Vista and Windows 7, and should be a wake-up call to organizations still running Windows XP to accelerate their migration plans.”
Given the in-the-wild exploit code, Lumension is recommending…