Danger! Unpatched Microsoft security vulnerability being actively exploited

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Sophos said:
An unpatched critical security vulnerability in Microsoft's software is being actively exploited by cybercriminals.

The exploit allows what's known as a drive-by install: you can become infected simply by visiting a website with Internet Explorer.

Alongside last week's regular Patch Tuesday announcement (including a remote code execution vulnerability that is being exploited by attackers in the wild), Microsoft also issued an out-of-band security advisory about an as-yet unpatched security hole (known as CVE-2012-1889).

microsoft-advisory.jpg


Read more: http://nakedsecurity.sophos.com/2012/06/19/unpatched-microsoft-security-vulnerability-exploited/
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,224
Thanks for the heads up Jack.
Doing that fix right now.
 

Ink

Administrator
Verified
Staff Member
Jan 8, 2011
22,491
Thanks for the heads up, I'll wait for a Windows Update (whenever that may be). :D
 

Ink

Administrator
Verified
Staff Member
Jan 8, 2011
22,491
ranget said:
why they didn't released the update yet ?

Because there is no patch for it yet, however they have released a Fix it solution.

No patch, no Windows Update for the wider audience.
 

Gnosis

Level 5
Apr 26, 2011
2,779
Great heads-up, but Microsoft is usually 30-60 days late with patches, so we can only control so much on our end.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top