The reporting around this one is really poor. There are far more reasons to be encouraged than there are reasons to be alarmed, or disagree.
First up would be mitigations available to many users [not all, or enough, yet, but many].
Users running systems with NX, or zero execute bit features as found on about all systems built in the last two years would have hardware support for Data Execution Protection [DEP] - enabled by default since XP SP2 in Aug 2004. DEP prevents buffer overruns from allowing arbitrary code execution. Vista extends this, greatly. For Vista users, IE 7's protected mode and UAC would have prevented users from being harmed - in other words, just as advertised, Vista's more comprehensive approach to security, works.
Second, and perhaps most importantly, the vulnerability was reported responsibly and it was acted upon - Microsoft's first response coming the same day the vulnerability was reported.
Third the testing of the out-of-band ptch was so complete, that both a work around for a faulty RealTek driver and a hotfix were supplied for affected users.
Fourth, going back many months, IE 7 developers, security researchers and developers from Mozilla/Firefox began to work together to better secure Windows users - with "Protected Mode" for Firefox being discussed and developed for future releases.
Finally, once the story broke, Microsoft made the patch it had been working on for months, available a week ahead of schedule.
If any of us should be pissed, we ought to be directing our anger at the criminals exploiting this and the press for causing us to jump through hoops and rush to push out a patch that we could have installed normally a week later.
We should all be looking at how much better the entire process is working - fewer vulnerabilities overall, slower propagation of the exploits and well mitigated affects by virtue of increased and layered protections being available, and increased cooperation and joint development between competitors who appear to be at least as interested in the end user as they are in beating one another over the head.
As an example of a serious vulnerability and how much better the response has been, the .ANI vuln should serve as reason to be encouraged and celebrated as an example that if we continue to work hard, we can stay ahead of the criminals trying to hurt all of us.
|