We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

Emergency Microsoft update fixes 10 bugs

Long-standing Internet Explorer flaw fixed

Microsoft has shipped 2010's second rush update for Internet Explorer (IE), patching 10 vulnerabilities - including one hackers have been exploiting for weeks.

That bug had been reported to Microsoft by a Beijing security company before news broke that it was being used by attackers. In fact, Microsoft wrapped up work on the fix for IE6 by February 26, according to date stamps on the affected file.

The update, labelled MS10-018, was released two weeks early because Microsoft had tracked a growing number of attacks against IE6 and IE7. The bug has been used by malicious sites to launch drive-by attacks for much of the month.

The last emergency IE update was issued January 21 to fix eight flaws, including one that had been exploited to attack Google, Adobe and scores of other companies. Google blamed China for the attacks, a move that led to its decision to relocate its Chinese-language search engine to Hong Kong.

All 10 vulnerabilities patched in yesterday's update - which was originally scheduled for release on April 13, the next regularly-scheduled Patch Tuesday - were rated 'critical', the highest level threat in Microsoft's four-step scoring system. But there were clear differences in the risk profiles of different versions of IE.

IE6, the 2001 browser that many want to see dead and buried, was affected by eight of the 10 bugs, with seven of those eight marked critical. IE7, which debuted in 2006 prior to the release of Windows Vista, contained seven out of the possible 10, with five vulnerabilities tagged critical. IE8, on the other hand, was touched by just three of the 10, with only two critical.

"The message today should be to get onto IE8," said Andrew Storms, director of security operations at nCircle Network Security. "Not just ditch IE6, but dump IE6 and IE7."

See also:

Internet Explorer 8 review

Web browser reviews

PC security advice

IDG UK Sites

Best camera phone of 2015: iPhone 6 Plus vs LG G4 vs Galaxy S6 vs One M9 vs Nexus 6

IDG UK Sites

In defence of BlackBerrys

IDG UK Sites

Why we should reserve judgement on Apple ditching Helvetica in OS X/iOS for the Apple Watch's San...

IDG UK Sites

Retina 3.3GHz iMac 27in preview: Apple cuts £400 of price of Retina iMac with new model