IE exploit unofficial patches



While we wait for Microsoft to release a patch for the MOST recent Internet Explorer vulnerability….. it looks as though MS is “planning” to release a patch on their routine patch day of April 11th. (However they could always change their mind…) As before though there are some 3rd party patches. I’ve got to say I’m slightly uncomfortable with the prospect of a third party patch when there are workarounds (use another browser, disable active scripting….) However, for some those aren’t enough options. I know of two unofficial patches.


Three if you count firefox… ;-)

Anyway, eEye Digital Security is the maker of one, which will remove itself when Microsoft’s fix is installed. Determina also has a “standalone fix”.

With regards to third party patches. Be very cautious. I have not tested either of these. My feeling is they would pose no great risk given the sources. (I’d be more likely to trust the eEye patch from their reputation – nothing against Determina, I just don’t recall having heard of them.) I WOULD test these thoroughly on a sacrificable/sandboxed system before daring to push out use to any other systems. AND most importantly I’d question if it’s really worth the risk of trying a third party patch when there are other options. (I know disabling active scripting can have frustrating consequences.)

That much said, I also know it’s nice to have options.

Related Posts

Blog Traffic Exchange Related Posts
  • Out of Cycle Windows Update - Patch Today Yesterday news broke of an out of cycle security patch for Windows. The bulletin is available from Microsoft. Apparently the vulnerability was in the Windows Server service (XP, 2003, 2000, 2008, Vista ALL affected though regardless of server/workstation/client/desktop/etc...). The RPC handling (remote procedure call) is the achilles heel this time......
  • Microsoft Releasing out of Cycle Patch for Internet Explorer Exploit Take a look at the official announcement. They've moved outside the usual update cycle for this one. VERY good move Microsoft to get this patch in before the holidays as it looks as though there's been a spike in the use of this particular exploit and with people doing a......
  • WMF unofficial patch updated There's been an update to the unofficial patch for the WMF (Windows MetaFile) vulnerability. The main change appears to be some options to allow for quiet installation (unattended) to help administrators in large environments try to roll the patch out in automated login scripts/etc. It can be found here or......
Blog Traffic Exchange Related Websites
  • Is the Brother Printer HL2270DW Wireless Monochrome Printer A Top-Quality Wireless Laser Printer? If you hardly print in color at all, the HL2270D wireless printer by Brother is a terrific printer. If you are interested in a good monochrome wireless printer, the consumer reviews for the Brother Printer HL2270DW have been positive. The Brother Printer HL2270DW is really simple to setup once you......
  • Conflicker - I mean, seriously If you don't already know, conflicker is a worm that exploits a buffer overflow in the windows server service.  The worm is wiley - there are several hundred variants and it is difficult to know how widespread it is.  You can find more info on the Wiki or on the......
  • Linux and the Fight for Freedom This is a guest post! If you want to write for us, check out the Guest Post section. Linux users are the freedom fighters of computing. They love their independence, and they’re not going to give that up for anything. Like their counterparts, though, they also need a little structure.......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site