Since the Nimda worm this fall exploited a common vulnerability in Internet Explorer, one would think that Microsoft might make it easy for you and me to get our browsers up-to-date. Unfortunately, Microsoft has elected to continue its policy of piecemeal patches, even in the wake of this costly worm attack.
Nimda exploited a vulnerability in Internet Explorer called "automatic execution of embedded MIME types." The worm created a JavaScript-infected Web page on infected servers that offered browsers a MIME type known as "audio/x-wav." Vulnerable Internet Explorer browsers used to preview this MIME type executed its malicious payload without the users' input. That's one of the ways Nimda jumped from Web servers to desktop PCs.
|