Security researchers have released a patch they claim fixes “an outstanding IE vulnerability” that Microsoft has not addressed. The Register reports that “the ad-hoc group of security pros,” called the Zeroday Emergency Response Team. ZERT says the patch addresses the Vector Markup Language (VML) vulnerability in IE, “the most serious of two unpatched IE vulnerabilities.” “Hackers are taking advantage of this VML security flaw in IE to infect users visiting pornographic websites. Opening maliciously constructed emails in Outlook is also a potential risk, especially as attacks targeting the vulnerability are growing in prevalence since their first appearance last week,” the site reports. No comment from Redmond. Maybe Bill’s too busy working on this MySpace page. Via The Register
Security pros release rogue IE patch
Opinion
Sep 26, 20061 min





