26 Jan 2010
Internet Explorer

A white-hat hacker alerted Microsoft to the security hole in August 2009 and it took several high-profile cyber attacks for a fix to be issued.

Microsoft was first alerted to the Internet Explorer flaw used in the Google attacks back in Augusut 2009 after a white-hat hacker at BugSec reported the vulnerability to the software giant.

The hole was scheduled for plugging in the next batch of security updates due in February, but the targeted attacks against Google, Adobe and up to 32 other American firms in China forced the software giant to release a patch much quicker.

It's become apparent that the vulnerability wasn't just limited to Internet Explorer either, as it can also be exploited by including an ActiveX control in Word, Excel, PowerPoint or Excel files.

A malicious hacker could build a spoofed website to gain access to the same user rights as any web user landing on the site. Security outfit Kaspersky said that if the user attempted to log into the malicious site, the attacker could take complete control of an affected system using the vulnerability.

The Internet Explorer update applies to all versions of the browser on all Windows versions, patching at least eight vulnerabilities that could lead to harmful attacks using remote execution.

