Microsoft releases patch for three critical holes in IE

Microsoft on Friday released an out-of-cycle patch to fix three critical and previously disclosed holes in Internet Explorer. The company also released an updated version of a software tool for cleaning out the prolific Mydoom virus and its variants from infected systems.

The latest cumulative patch is contained in Security Bulletin MS04-25 and is aimed at fixing a series of flaws in Internet Explorer that were publicly disclosed in late June.

Microsoft, which typically releases patches in monthly cycles, urged users to install the latest one as soon as possible because of potentially serious risks posed by the flaws.

For instance, one of the holes has already been in an attack called Download.Ject in which vulnerable client systems are infected with a Trojan horse capable of capturing sensitive information, such as log-on names and passwords, or of fooling users into parting with their credit card numbers and ATM codes.

Microsoft released a tool to help users get rid of the Trojan on infected systems in June. On July 2, the company released a configuration change to Windows XP, Server 2003 and Windows 2000 that was designed to mitigate the risk posed by Download.Ject.

Today's patch finally closes the so-called cross-domain vulnerability in Internet Explorer that Download.Ject takes advantage of, Microsoft said.

There is no evidence that the other two flaws addressed by the latest patch have been exploited, said Alfred Huger, senior director of engineering at Symantec Corp.'s security response center.

One of them is a buffer overflow vulnerability in a software component used to process bitmap image files. The other is a buffer overrun flaw in a function used to process GIF image files. Both flaws could give attackers a way to remotely execute malicious code on an infected system.

"Both of these are a little more difficult to exploit than the first one," Huger said. "We haven't seen any exploits so far but that doesn't necessarily mean there aren't any," he said.

Microsoft's latest patch replaces the MS04-004 cumulative update that was first issued by the company in February and later updated in April.

Meanwhile, the company's tool for removing the latest Mydoom variant from infected systems is available at www.microsoft.com/security/incident/mydoom.mspx.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jaikumar Vijayan

Computerworld
Show Comments

Cool Tech

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Breitling Superocean Heritage Chronographe 44

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?