Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Internet Explorer

June 10th, 2009, 09:20 GMT · By

Patch Critical Holes in IE8 and IE7 on Vista SP2/SP1 and XP SP3

SHARE:

Adjust text size:


Internet Explorer 8
Enlarge picture
As an integral part of this month's release of security bulletins, Microsoft has made available the IE Cumulative Security Update for June 2009 through its Windows Update or Microsoft Update distribution channels. The cumulative refresh for Internet Explorer contains patches for no less than eight vulnerabilities affecting various versions of the Redmond company's proprietary browser. “This update addresses seven privately reported vulnerabilities and one publicly disclosed vulnerability. The security update addresses these vulnerabilities by modifying the way that Internet Explorer handles scripts, cached content, and initializes memory,” explained Terry McCoy, program manager, Internet Explorer Security.

Not all IE releases are impacted by the vulnerabilities patched this month by the software giant. Internet Explorer 8 for example contains only the HTML Objects Memory Corruption Vulnerability, which comes with a maximum severity rating of Critical on both Windows XP (SP2 and SP3) and Windows Vista (SP1 and SP2).

“A remote code execution vulnerability exists in the way Internet Explorer accesses an object that has not been correctly initialized or has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights,” reads Microsoft's explanation of the HTML Object Memory Corruption flaw.

By contrast, Internet Explorer 7 running on the same two client platforms is affected by no less than six vulnerabilities. Four of the security updates designed to plug the holes in IE7 are considered Critical. The remaining two have been labeled just Important. This is valid for IE7 running on Vista RTM/SP1/SP2 and for XP SP2 and SP3.

“This security update is rated Critical for Internet Explorer 5.01 on Windows 2000, Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on supported editions of Windows XP and Windows Vista. The security update is rated Important for Internet Explorer 6 Service Pack 1 on support editions of Windows 2000. The security update is rated Moderate for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on supported editions of Windows Server 2003 and Windows Server 2008,” McCoy added.

Internet Explorer 8 (IE8) RTW is available for download here (for 32-bit and 64-bit flavors of Windows XP, Windows Vista, Windows Server 2003 and Windows Server 2008).

Windows Server 2008 Service Pack 2 and Windows Vista Service Pack 2 - Five Language Standalone (KB948465) is available for download here.

Windows Server 2008 Service Pack 2 and Windows Vista Service Pack 2 - Five Language Standalone for x64-based systems (KB948465) is available for download here.

TELL US WHAT YOU THINK:

5,781 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


IE8 RTW – Download New Wave of Releases

Microsoft Translator Gets Any-to-Any Translations and Language Autodetect

Microsoft Will Not Get to Defend IE-Windows Bundle in EU

Internet Explorer 8 RTW MUI Packs for XP SP3

IE8 RTW Display Mixed Content Changes

READER COMMENTS:


Comment #1 by: guest on 10 Jun 2009, 11:48 UTC reply to this comment

“This security update is rated Critical for Internet Explorer 5.01 on Windows 2000, Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on supported editions of Windows XP and Windows Vista. The security update is rated Important for Internet Explorer 6 Service Pack 1 on support editions of Windows 2000. The security update is rated Moderate for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on supported editions of Windows Server 2003 and Windows Server 2008,” McCoy added. "


does anyone but me feel that this is untrue? several months without IE updates, no vulnerabilities found and they were efforting only in IE8 and now previous ones has flaws again?...what is MS trying to install on us ? :P and whatbout publishing software for what it is? i dont recall any soft company that has more updates than MS...make us wonder..

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM