IE exploit unofficial patches



While we wait for Microsoft to release a patch for the MOST recent Internet Explorer vulnerability….. it looks as though MS is “planning” to release a patch on their routine patch day of April 11th. (However they could always change their mind…) As before though there are some 3rd party patches. I’ve got to say I’m slightly uncomfortable with the prospect of a third party patch when there are workarounds (use another browser, disable active scripting….) However, for some those aren’t enough options. I know of two unofficial patches.


Three if you count firefox… ;-)

Anyway, eEye Digital Security is the maker of one, which will remove itself when Microsoft’s fix is installed. Determina also has a “standalone fix”.

With regards to third party patches. Be very cautious. I have not tested either of these. My feeling is they would pose no great risk given the sources. (I’d be more likely to trust the eEye patch from their reputation – nothing against Determina, I just don’t recall having heard of them.) I WOULD test these thoroughly on a sacrificable/sandboxed system before daring to push out use to any other systems. AND most importantly I’d question if it’s really worth the risk of trying a third party patch when there are other options. (I know disabling active scripting can have frustrating consequences.)

That much said, I also know it’s nice to have options.

Related Posts

Blog Traffic Exchange Related Posts
  • Windows 98 won't see the MS06-15 patch It turns out that Windows 98 is just too hard for Microsoft to support with a security patch for MS06-15 now. The official support period ends in July, but they've announced that this one won't be getting a patch as the changes would be just too substantial. Some of the......
  • Microsoft security roundup OK - there have been a number of Excel problems floating around in the last week - week and a half. Securiteam blog has a FAQ on the Excel 0-day vulnerabilities with Excel and Excel Viewer Incidents.org kindly gives us a scoresheet documenting the three different vulnerabilities that have been......
  • Microsoft Releasing out of Cycle Patch for Internet Explorer Exploit Take a look at the official announcement. They've moved outside the usual update cycle for this one. VERY good move Microsoft to get this patch in before the holidays as it looks as though there's been a spike in the use of this particular exploit and with people doing a......
Blog Traffic Exchange Related Websites
  • Conflicker - I mean, seriously If you don't already know, conflicker is a worm that exploits a buffer overflow in the windows server service.  The worm is wiley - there are several hundred variants and it is difficult to know how widespread it is.  You can find more info on the Wiki or on the......
  • Prosper Starting To Use the Developer Mailing List I have been a member of the Prosper developer mailing listing since the list's inception... This is the 1st instance of using the list.  They made the relevant announcement.  Kudos! (it is about time) Here is the email... Prosper is experiencing two issues that may be affecting your applications and code.......
  • Is the Brother Printer HL2270DW Wireless Monochrome Printer A Top-Quality Wireless Laser Printer? If you hardly print in color at all, the HL2270D wireless printer by Brother is a terrific printer. If you are interested in a good monochrome wireless printer, the consumer reviews for the Brother Printer HL2270DW have been positive. The Brother Printer HL2270DW is really simple to setup once you......
en.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site