quinta-feira, 25 de março de 2010

Exploits of unpatched IE6, IE7 flaw on the rise

URL: http://feeds.arstechnica.com/~r/arstechnica/index/~3/YfFFN64Z_Vo/exploits-of-unpatched-ie6-ie7-flaw-on-the-rise.ars


An unpatched flaw in Internet Explorer versions 6 and 7 is increasingly being exploited. The flaw, first reported two weeks ago, was initially used in limited, targeted attacks. It is now evolving into something more widespread and indiscriminate.

Security researchers for antivirus company AVG are now reporting tens of thousands of attacks per day, and this number is likely to grow further. Rival firm Trend Micro has reported similar growth. It appears that there are now two main attacks being used by two separate gangs of hackers; one installs fake antivirus software, the other installs a trojan.

Redmond is yet to release (or even announce) a patch, though an automated workaround is now available. The next Patch Tuesday is not until April 13, so if the growth in exploitation continues, the company will be under increasing pressure to publish a update sooner. There is, however, one robust fix already available: upgrade to Internet Explorer 8. The newest browser version doesn't contain the flaw at all.

Read the comments on this post


Nenhum comentário: