EEye has engineered the patch to automatically remove itself when Microsoft's official patch comes through
EEye Digital Security has created a temporary patch for Microsoft's Internet Explorer
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Security firm plugs Internet Explorer hole

Workaround promises to protect browser in anticipation of official fix

Tom Sanders in California, vnunet.com 28 Mar 2006
ADVERTISEMENT

Security vendor eEye Digital Security has created a temporary patch that protects end users and enterprises from an unpatched vulnerability in Internet Explorer

The vulnerability is caused by an error in the way that the browser processes a 'createTextRange' call on a radio button. The bug could allow attackers to take control of a system by luring victims to a specially crafted website.

Attackers are actively exploiting the flaw and Microsoft has hinted that it might release an out of cycle patch.

The Redmond giant had advised users to disable Active Scripting in their browser settings (instructions can be found at Microsoft's support website). 

Microsoft has not certified the eEye patch. The security firm recommended that users try disabling Active Scripting first and use its workaround only if this does not work.

"EEye's patch is not meant to replace the forthcoming Microsoft patch, but to provide immediate protection in lieu of an available fix," said Marc Maiffret, co-founder and chief hacking officer at the security company.

"In fact, eEye has engineered the patch to automatically remove itself when Microsoft's official patch comes through."


All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
South West, Darlington, United Kingdom | University College Falmouth
  Web Sharepoint Development Manager, £23,692-£26,665 (£29,138) per annum (Grade 5) The creation of a new University for the Arts in the South West has taken a major step forward with the merger of University ... more >
Chichester, United Kingdom | West Sussex County Counci
Application Specialist, Chichester, £26,400 - £28,600 pa (includes Market Rate Supplement) IT Services at WSCC supports and manages a variety of systems based on Oracle databases that include third party and bespoke applications as well ... more >
Sutton, Surrey, United Kingdom | Royal Marsden Hospital NHS Trust
  The Royal Marsden NHS Foundation Trust is a centre of excellence for research, development, education and care in the treatment of cancer. Analyst Programmers, Band 6, £23,458-£31,779 plus 15% HCAS, Sutton, Surrey We are ... more >
TWICKENHAM, United Kingdom | Rugby Football Union
RUGBYFIRST PROJECT MANAGER, TWICKENHAM, c. £40,000 per annum   12 month fixed term RugbyFirst, the most modern administration system in British sport, is a game-wide internet-based tool to help run rugby at all levels, with the ... more >
More job opportunities