Microsoft on Tuesday was to release an out-of-band emergency patch for Internet Explorer. Security update MS10-018 was to roll out at approximately 1 p.m. EST to address a publicly disclosed vulnerability in Internet Explorer 6 and 7.
p
Jerry Bryant, group manager for the response communications team at the Microsoft Security Response Center, recommends customers install the update as soon as it’s available. Because it’s a cumulative update, it will also address nine other vulnerabilities in Internet Explorer, some of which affect IE 8, that were planned for release on April 13.
p
Once applied, customers are protected against the known attacks related to Security Advisory 981374, said Bryant. We have been monitoring this issue and have determined an out-of-band release is needed to protect customers. For customers using automatic updates, this update will automatically be applied once it is released.
p
subhead
Hackers Actively Exploiting IE
/subhead
p
Hackers have been actively exploiting the IE vulnerability for a couple of weeks now, attempting to infect computers by luring unsuspecting users to click on dangerous links, said Graham Cluley, a senior security consultant at Sophos. He’s not surprised, then, to see Microsoft breaking its normal patch schedule.
p
Of course, if people had already upgraded to Internet Explorer 8, then they wouldn’t have to be patching their systems. In many ways this can be considered another nail in the coffin of the now ancient and woefully poor Internet Explorer 6, Cluley said.
p
The big question is, when will we stop nailing the coffin lid down and finally bury it! If you haven’t already thought about your migration plan from IE 6 or 7 to IE 8, or perhaps an alternative browser, now might be the time to give it serious consideration, he added.
p
subhead
Apple Plugs Security Holes
/subhead
p
Microsoft isn’t the only tech giant issuing fixes this week. On Monday, Apple released a major update…