cancel
Showing results for 
Search instead for 
Did you mean: 
Hayton
Level 17

Microsoft issues emergency FixIt for Internet Explorer

This looks like a temporary measure until the unscheduled update is released for IE on September 21st

(see http://technet.microsoft.com/en-us/security/bulletin/ms12-sep)

Malware exploiting the vulnerability reported in IE has already been seen, and the standard mitigation procedures for Windows (DEP, ASLR) may not be effective against it.

If you use IE, you're vulnerable to attack - especially if you use IE7 or IE8 on XP. Some security experts have been saying that all versions of IE except IE10 are totally unsafe until this is fixed and you should switch to another browser.

Microsoft's temporary patch is a FixIt available at

http://support.microsoft.com/kb/2757760

For more details about this see

http://technet.microsoft.com/en-us/security/advisory/2757760

http://blogs.technet.com/b/msrc/archive/2012/09/19/internet-explorer-fix-it-available-now-security-u...

This article discusses the use of Microsoft's EMET to protect applications against many common types of exploit :

https://krebsonsecurity.com/2012/09/internet-explorer-users-please-read-this/


Message was edited by: Hayton on 21/09/12 06:32:36 IST

Message was edited by: Hayton - add link to Brian Krebs article -  on 22/09/12 16:31:03 IST
0 Kudos
23 Replies
exbrit
Level 21

Re: Microsoft issues emergency FixIt for Internet Explorer

Thanks.. I will now see about applying this to my numerous systems.   I'll probably wait for the update to appear in the normal manner, however.  No need to panic.

Message was edited by: Ex_Brit on 21/09/12 7:14:14 EDT AM
0 Kudos
exbrit
Level 21

Re: Microsoft issues emergency FixIt for Internet Explorer

One strange anomaly...the Fixit only goes as high as IE9, or so it says, but the Advisory is for all versions including IE10, as in Windows 8.   What is going on?   Now I am in 2 minds as to whether or not to try to apply the FIXIT to all systems or wait and see if the update.comes in for my Windows 8 later today.

0 Kudos
exbrit
Level 21

Re: Microsoft issues emergency FixIt for Internet Explorer

Well that was easy....the Fixit doesn't apply to IE10.  Tried and failed.

Message was edited by: Ex_Brit on 21/09/12 7:52:32 EDT AM
0 Kudos
sol
Level 8

Re: Microsoft issues emergency FixIt for Internet Explorer

Here is the MS article regarding this

General Information

  Executive Summary

Microsoft is investigating public reports of a vulnerability in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, and Internet Explorer 9. Internet Explorer 10 is not affected

http://technet.microsoft.com/en-us/security/advisory/2757760

0 Kudos
exbrit
Level 21

Re: Microsoft issues emergency FixIt for Internet Explorer

Already linked in Hayton's post, but what I'm wondering about is why the Fixit only goes as high as IE9, leaving IE10 users in the dark so to speak.

I guess time will tell when and if the update comes in for Windows 8 later today.    It isn't yet on Microsoft's update servers.

I'd rather wait for an update than install extra tools.

0 Kudos
exbrit
Level 21

Re: Microsoft issues emergency FixIt for Internet Explorer

I need new glasses....'Non affected software : IE10".....sigh, sorry for the minor panic.

sol
Level 8

Re: Microsoft issues emergency FixIt for Internet Explorer

You saved me from smacking my head against the wall...  It's not uncommon for me to be the blind one.

0 Kudos
exbrit
Level 21

Re: Microsoft issues emergency FixIt for Internet Explorer

I am now slinking away into a corner in embarrassment.   ;-)

0 Kudos
sol
Level 8

Re: Microsoft issues emergency FixIt for Internet Explorer

haaahhaahahahah ... Thank you for starting my day off with a good chuckle and a smile to last 8.5 hours.

This wass better than the fact that it is Friday and payday all in one.

0 Kudos