Microsoft Patches Serious IE Flaw
Microsoft doesn't wait for the second Tuesday to release a patch for dangerous vulnerability that lets attackers trick Internet users into visiting malicious sites.Microsoft Corp. on Monday finally released a patch for a dangerous vulnerability that lets attackers trick Internet users into visiting malicious sites. The flaw has been public knowledge for some time, but Microsoft failed to include a fix for it with Januarys scheduled patch releases. The vulnerability has to do with the way IE parses URLs, specifically those that contain special characters. Using this weakness, an attacker can create a link that looks like it will send a user to a legitimate site, such as www.eweek.com. However, once the user clicks on the link, the attacker can cause content from another site to appear in the window.
Microsoft typically releases security fixes on the second Tuesday of each month. But the seriousness of this vulnerability caused the company to publish this patch out of cycle.