Microsoft to Fix Internet Explorer Security Hole on Patch Tuesday

Microsoft to Fix Internet Explorer Security Hole on Patch Tuesday

Written By
Brian Prince
Brian Prince
Dec 3, 2009
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Microsoft is planning to release six security bulletins for December’s Patch Tuesday, including one to cover the recently disclosed zero-day vulnerability affecting Internet Explorer.

According to the prerelease advisory, three of the bulletins are rated critical. The remaining bulletins are rated important. All told, Microsoft will address 12 vulnerabilities in Windows, Internet Explorer and Microsoft Office products.

The Internet Explorer vulnerability, discussed by Microsoft in a security advisory, affects Internet Explorer 6 and 7. The vulnerability is an invalid pointer reference of IE. In certain situations, a CSS/Style object can be accessed after the object is deleted. In a specially crafted attack, Internet Explorer attempting to access a freed object can lead to running attacker-supplied code, Microsoft warned.

“The IE update maps to bulletin No. 4 in the ANS and will be at the top of our deployment priority list,” blogged Jerry Bryant, security program manager for Microsoft Security Response Center. “The other critical update affecting Windows (bulletin No. 1) will have a lower Exploitability Index rating, so while the impact is higher with a critical severity rating, the lower risk will drop the deployment priority down a little. The final critical update affecting Microsoft [Office] Project (bulletin No. 3) is only critical for Project 2000.”

The updates are scheduled to become available Dec. 8.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.