MARCH 27, 2006 (IDG NEWS SERVICE) - With Microsoft Corp. saying that it may wait until April 11 to patch a critical vulnerability in its Internet Explorer browser, security vendor eEye Digital Security has released what it calls a "temporary" patch to address the problem.
The bug, which concerns the way IE processes Web pages using the createTextRange() method, is now being exploited by attackers on hundreds of malicious Web sites (see "Update: Microsoft tests fix for IE bug as exploits appear"). Users who might be tricked into visiting these Web sites could have unauthorized software installed on their computers, security experts warn.
Though Microsoft has described these attacks as "limited" in scope, the problem is being taken seriously by the software maker because the exploits can be used to seize control of a user's machine.
|