Tuesday, February 8, 2011

Microsoft reports new IE security flaw

Recently Microsoft reported a potentially serious security flaw in Internet Explorer in every currently supported version. This means that those of us that still use IE for any Internet access are at risk. The vulnerability affects MHTML and although their is published code that proves the vulnerability can be exploited, no cases of this method being used in the wild have been reported.

Microsoft has provided both automated "Fix It" and manual procedures to fix it yourself in this MS knowledge base article. This does not actually fix the flaw but locks down the MHTML system to prevent an attack from being successful.

If you still use Internet Explorer please click on the links above and read the advisory and then implement the workaround for your system. It only takes a minute to do but will help to secure your system.

Remember, security is not a passive activity and requires vigilance and persistence to defeat the attacks.

No comments:

Post a Comment