Microsoft patches fix that crashes Internet Explorer

Share this article:

Updated Friday, Dec. 21 at 12:48 p.m. EST

Microsoft has released an automated workaround through its download center to resolve a glitch in a recently released cumulative Internet Explorer 6 (IE6) patch that can cause the popular browser to crash, the company said Friday.

The fix comes two days after Microsoft offered a manual workaround to resolve the glitch.

The software giant admitted late Tuesday to "possible problems on systems that have installed" the fix, MS07-069, considered by experts to be the most pressing patch to come out of this month's security release. The affected computers are those running Windows XP Service Pack 2.

On Wednesday, Microsoft released a support document that offers users a nine-step registry-edit workaround to correct the glitch.

Kieron Shorrock, program manager for IE inside the Microsoft Security Response Center, said the company has been working with a small number of customers on the issue.

Some experts had questioned why Microsoft chose not to release a new patch.

"This is a large-scale issue because IE6 is the most popular version of the browser," said Paul Zimski, senior director of market strategy at Lumension Security, a security management firm. "Microsoft has yet to issue a fix and its temporary workaround does not guarantee to correct the problem."

Mark Miller, Microsoft's director of security response, told SCMagazineUS.com in an email Thursday that the software company may issue a hotfix so customers will have no problems applying the workaround.

The original IE patch plugged four holes in the browser, garnering an "extremely critical" label from vulnerability tracking firm Secunia. Since the patch was released, attackers began actively exploiting the flaws, Secunia said.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

More in News

CryptoWall surpasses CryptoLocker in infection rates

CryptoWall surpasses CryptoLocker in infection rates

A threat analysis from Dell SecureWorks CTU says that CryptoWall has picked up where its famous sibling left off.

Professor says Google search, not hacking, yielded medical info

Professor says Google search, not hacking, yielded medical ...

A professor of ethical hacking at City College San Francisco came forward to clarify that he did not demonstrate hacking a medical center's server in a class.

Syrian Malware Team makes use of enhanced BlackWorm RAT

Syrian Malware Team makes use of enhanced BlackWorm ...

FireEye analyzed the hacking group's use of the malware, dubbed the "Dark Edition" of BlackWorm.