Microsoft warns on IE security flaw

2012-09-18 08:25
Microsoft has urged IE users to download a security patch. (Steven Senne, AP)

Microsoft has urged IE users to download a security patch. (Steven Senne, AP)

Multimedia   ·   User Galleries   ·   News in Pictures Send us your pictures  ·  Send us your stories

kalahari.com

Boston - Microsoft warned a newly discovered bug in its Internet Explorer web browser makes PCs vulnerable to attack by hackers and urged customers to download a piece of security software to mitigate the risk of infection.

The security flaw affects hundreds of millions of Internet Explorer browser users. Microsoft said attackers can exploit the bug to infect the PC of somebody who visits a malicious website and then take control of the victim's computer.

The software maker advised customers on its website late on Monday to install the security software as an interim measure, buying it time to fix the bug and release a new, more secure version of Internet Explorer. The company did not say how long that will take, but several security researchers said they expect the update within a week.

The free security tool, which is known as the Enhanced Mitigation Experience Toolkit, or Emet, is available through an advisory on Microsoft's website.

The Emet software must be downloaded, installed and then manually configured to protect computers from the newly discovered threat, according to the posting from Microsoft. The company also advised customers to adjust several Windows security settings to thwart potential attackers, but cautioned that doing so might impact the PC's usability.

Cumbersome

Some security experts said it would be too cumbersome for many PC users to implement the measures suggested by Microsoft. Instead, they advised Windows users to temporarily switch from Internet Explorer to rival browsers such as Google's Chrome, Mozilla's Firefox or Opera Software ASA's Opera .

"For consumers it might be easier to simply click on Chrome," said Dave Marcus, director of advanced research and threat intelligence with Intel Corp's McAfee security division.

Marc Maiffret, chief technology officer of the security firm BeyondTrust, said it may not be feasible for some businesses to install Microsoft's Emet tool on their PCs.

He said the security software has in some cases proven to be incompatible with existing programs already running on networks.

Tod Beardsley, an engineering manager with the security firm Rapid7, said that at first blush it appeared that the Emet may not be particularly effective in thwarting potential attacks.

Microsoft officials declined to comment on the scepticism that those security experts expressed about the effectiveness of the Emet software.

Eric Romang, a researcher in Luxembourg, discovered the flaw in Internet Explorer on Friday, when his PC was infected by a piece of malicious software known as Poison Ivy that hackers use to steal data or take remote control of PCs.

Unknown bug

When he analysed the infection, he learned that Poison Ivy had exploited a previously unknown bug on his system, or "zero-day" vulnerability, in Internet Explorer.

"Any time you see a zero-day like this, it is concerning," said Liam O Murchu, a research manager with anti-virus software maker Symantec. "There are no patches available. It is very difficult for people to protect themselves."

Zero-day vulnerabilities are rare, mostly because they are hard to identify - requiring highly skilled software engineers or hackers with lots of time to scrutinise code for holes that can be exploited to launch attacks. Security experts only disclosed discovery of eight major zero-day vulnerabilities in all of 2011, according to Symantec.

Symantec and other major anti-virus software makers have already updated their products to protect customers against the newly discovered bug in Internet Explorer. Yet, O Murchu said that may not be sufficient to ward off adversaries.

"The danger with these types of attacks is that they will mutate and the attackers will find a way to evade the defences we have in place," he said.

Internet Explorer was the world's second-most widely used browser in August, with about 33% market share, according to StatCounter. It was close behind Chrome, which had 34% of the market.

Read more on:    microsoft  |  internet  |  cyber crime
NEXT ON NEWS24X

Read News24’s Comments Policy

24.com publishes all comments posted on articles provided that they adhere to our Comments Policy. Should you wish to report a comment for editorial review, please do so by clicking the 'Report Comment' button to the right of each comment.

Comment on this story
15 comments
Add your comment
Comment 0 characters remaining
 

Inside News24

 
 

Tattoos for Pets – To Ink or not to Ink?

An American tattoo artist has created controversy with his latest ink job.

 
 

More pet-centric news...

Happy birthday Garfield!
Huge snake opens door
Bag it – China’s live animal keychain trend
Hitchhiking cat headed home
 
Traffic
Lottery
 
  • Thursday Citrusdal - 16:22 PM
    Road name: N7
    ROADWORKS - stop / go controls in operation between Citrusdal and Clanwilliam (until 2014)
  • Monday Ventersburg - 05:24 AM
    Road name: N1
    ROADWORKS - construction works are underway with a deviation in operation just north of the town centre
 
More traffic reports...
 

Property [change area]

APARTMENTS / FLATS FOR SALE IN Sandton, Fourways

Apartments / Flats R 1 100 000

HOUSES FOR SALE IN Bedfordview

Houses R 2 750 000

HOUSES FOR SALE IN Westville

Houses R 6 999 000

Travel - Look, Book, Go!

Aquarius Suites - Blouberg Strand, Cape Town

Spend 2 nights for R2 710 per person sharing at Aquarius Suites - Blouberg. The special includes accommodation, return flights, airport taxes, car rental and local travel insurance.

Book now!

Kalahari.com - shop online today

Deal of the week, get up to 60% off!

Get up to 60% off DVDs, Blu-rays, Games and Music this week at kalahari.com. Offer valid while stocks last and ends 23 June. Shop now!

Get 30% off Deon Meyer titles

Buy any 2 Deon Meyer books from this catalogue and get 30% off. Offer valid while stocks last. Shop now!

Leapster GS explorer + Free game

Experience the fast-paced action in a sleek new design that’s packed with learning for kids plus get a free game. Shop now!

Asus 11.6 Touch sreen VivoBook

Save R1000 on the Asus 11.6 Touch screen with dual core processor, Windows 8, 2GB RAM and 500GB storage. Dispatched within 24hrs + free delivery. Buy now!

Ashes Cricket 2013

Get the official video game of the Ashes 2013 cricket series. Wii U, PS3, Xbox & PC available. Releasing this week. Shop now!

OLX Free Classifieds [change area]

Blackberry z10 (1 day old)

For Sale, Cell Phones - Accessories in South Africa, Gauteng, Johannesburg. Date May 13

Urgent Sale

Vehicles, Motorcycles - Scooters in South Africa, Gauteng, Johannesburg. Date May 13

Aupairs

Jobs, Au pairs & nannies in South Africa, Gauteng, Johannesburg. Date May 12

BlackBerry Bold 9790

Bold Design The BlackBerry Bold 9790 smartphone combines the iconic BlackBerry...

From R2999.00

I'm shopping for:

Horoscopes
Aquarius
Aquarius

You could feel touchy about your reputation at work today. If someone has let something slip that you found offensive, first...read more

There are new stories on the homepage. Click here to see them.
 
English
Afrikaans
isiZulu

Hello 

Create Profile

Creating your profile will enable you to submit photos and stories to get published on News24.


Please provide a username for your profile page:

This username must be unique, cannot be edited and will be used in the URL to your profile page across the entire 24.com network.

Settings

Location Settings

News24 allows you to edit the display of certain components based on a location. If you wish to personalise the page based on your preferences, please select a location for each component and click "Submit" in order for the changes to take affect.








Facebook Sign-In

Hi News addict,

Join the News24 Community to be involved in breaking the news.

Log in with Facebook to comment and personalise news, weather and listings.