Thursday, May 9, 2013

Internet Explorer users, get your free emergency patch right now

This one is extra nasty, because there are exploits spreading like wildfire on the 'net targeting Internet Explorer 8.  It's so bad that Microsoft has produced a secret squirrel patch (it's a "we're not telling you what the problem is until we have a proper patch, but trust us you want this RIGHT DAMN NOW" patch).  Yeah, you want this RIGHT DAMN NOW:
Microsoft is investigating public reports of a vulnerability in Internet Explorer 8. Microsoft is aware of attacks that attempt to exploit this vulnerability. Applying the Microsoft Fix it solution, "CVE-2013-1347 MSHTML Shim Workaround," prevents the exploitation of this issue. See the Suggested Actions section of this advisory for more information.

The vulnerability does not affect Internet Explorer 6, Internet Explorer 7, Internet Explorer 9, and Internet Explorer 10.

The vulnerability is a remote code execution vulnerability. The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.
The fix itself is a little hard to find.  To save you the trouble, I've tracked it down here.  Click the "Fix It" and you're set.  No reboot is required.

2 comments:

Old NFO said...

Thanks BP!!!

Ratus said...

Internet Explorer?

What is this "Internet Explorer" that you speak of.

I know not this thing.