Microsoft fixes browser flaw used in Google breach

January 22, 2010 07:13 pm | Updated November 17, 2021 07:10 am IST - SEATTLE

Microsoft said it learned of the problems last fall and was already planning to release the fixes in February.

Microsoft said it learned of the problems last fall and was already planning to release the fixes in February.

Microsoft Corp. took the unsual step of issuing an unscheduled fix on Thursday for security holes in its Internet Explorer browser that played a role in the recent computer attacks that led Google to threaten to leave China.

The updates are for all supported versions of Internet Explorer, from IE 5.01 up through the newest IE 8.

People who have their computers set to install security updates automatically will get the fix. PC users who don’t automatically get updates should go to www.microsoft.com/security to download the patch.

Microsoft said it learned of the problems last fall and was already planning to release the fixes in February. Last week, it confirmed that the attacks described by Google Inc. took advantage of the same flaw.

Hackers can lure people to Web pages containing malicious code, then exploit the browser flaw to take over their computers. Attackers in China may have used the flaw to break into e-mail accounts of human rights activists who oppose the Chinese government. Hackers may also have used this flaw, among others, to break into Google’s own networks and those of other large companies such as Yahoo Inc. and Juniper Networks Inc.

Microsoft seldom releases security patches outside its regular, once-a-month update cycle, but has been known to rush out patches for so-called “zero-day” exploits in which hackers attack a software hole before the company has a chance to find a fix. The last time Microsoft broke from its security update schedule was in July 2009.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.