Microsoft’s recent set of security patches is causing problems, namely for Internet Explorer 6 users, who are watching their browsers crash midstream when visiting some sites. Redmond has offered a technical workaround to solve the problem until a more formal fix can be developed.
“First, I want to note the security update does protect against the vulnerabilities noted in the bulletin,” Kieron Shorrock, Microsoft Security Response Center (MSRC) program manager responsible for Internet Explorer, wrote in the MSRC blog. The Internet Explorer patch fixes four critical vulnerabilities in the browser, making it the most important of December’s Patch Tuesday updates.
Shorrock said Microsoft has been working with a “small number” of customers who reported issues related to the browser resulting from the update described in security bulletin MS07-069. The problem generates a message that reads, “Internet Explorer has encountered a problem and must close.” The bug is not widespread, according to Microsoft, and only affects certain installations of Internet Explorer 6 on Windows XP.
Large-Scale Issue?
While Microsoft downplayed the bug, Paul Zimski, senior director of market strategy at Lumension Security, called the Internet Explorer problem a large-scale issue. The problem, he said, illustrates that the patch-management process is not one that administrators should treat as a checklist item.
“Microsoft has yet to issue a fix, and its temporary workaround does not guarantee to correct the problem. Uninstalling the patch is also not an ideal solution because it will leave a tremendous number of machines vulnerable,” Zimski said.
“To avoid similar issues in the future,” Zimski went on to say, “we recommend that organizations deploy solutions for developing customized, home-grown patches and other hot fixes as an added layer of protection against vulnerabilities in case vendor-issued patches do not work correctly.”
Internet Explorer 8 Beta
Meanwhile, Microsoft developers are working on Internet Explorer 8. The…