News

Microsoft Responds to IE Patch Complaints

Microsoft ran into one of its classic security flaps this week over the latest Internet Explorer cumulative patch.

An Israeli security firm, GreyMagic Software, accused Microsoft on Thursday and Friday of failing to address the underlying issues that led to some of the 6 new vulnerabilities that Microsoft patched on Wednesday in MS02-023.

GreyMagic's post to a popular security mailing list raises the familiar themes of shoddy quality control and prompted quick counterreplies from Microsoft.

Microsoft acknowledged one point in the GreyMagic posts, but Microsoft officials took the opportunity to criticize GreyMagic for going public instead of trying to work with Redmond first and for misunderstanding the root cause of the problems the original IE patch fixed. Instead, Microsoft officials said the problems GreyMagic found appear to be two new security issues with Internet Explorer.

Microsoft urged users to immediately install the patch it issued May 15, and promised it was looking into the new problems.

"While it's too soon to say what the two investigations will reveal, we do want to assure customers that we will take the appropriate steps to help them keep their systems secure," a Microsoft representative wrote in an official response from the Microsoft Security Response Center.

The security bulletin was the third cumulative patch for IE this year and the fifth since November 2001. In all, the five cumulative patches have included fixes for 20 newly discovered vulnerabilities, with critical problems in each cumulative patch.

Three of the vulnerabilities in the latest cumulative patch rate a critical designation on Microsoft's threat scale. A cross-site scripting in local HTML resource problem affects IE 6.0; a local information disclosure through an HTML object affects IE 5.01, 5.5 and 6.0; and a script within cookies reading cookies affects IE 5.5 and 6.0.

The security bulletin, with the patch, is available at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-023.asp.

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Surface and ARM: Why Microsoft Shouldn't Follow Apple's Lead and Dump Intel

    Microsoft's current Surface flagship, the Surface Pro X, already runs on ARM. But as the ill-fated Surface RT showed, going all-in on ARM never did Microsoft many favors.

  • IT Security Isn't Supposed To Be Easy

    Joey explains why it's worth it to endure a little inconvenience for the long-term benefits of a password manager and multifactor authentication.

  • Microsoft Makes It Easier To Self-Provision PCs via Windows Autopilot When VPNs Are Used

    Microsoft announced this week that the Windows Autopilot service used with Microsoft Intune now supports enrolling devices, even in cases where virtual private networks (VPNs) might get in the way.

  • Most Microsoft Retail Locations To Shut Down

    Microsoft is pivoting its retail operations to focus more on online sales, a plan that would mean the closing of most physical Microsoft Store locations.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.