|
ALARM Group ALERT ¿ click for a description of ALARM, The Computing Alert System Alert Number: 112205-01 Alert Date: 11/22/05 Alert Title: Microsoft releases security advisory to address Internet Explorer Exploit Update-to: 112105-01 "Proof of Concept code released for UNPATCHED MS Internet Explorer Exploit" OS/Platform/Application: Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4 Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4 Internet Explorer 6 (including Service Pack 1) on Microsoft Windows XP Service Packs 1 and 2 Internet Explorer 6 on Microsoft Windows XP Professional x64 Edition Internet Explorer 6 on Microsoft Windows Server 2003 (including Service Pack 1) Internet Explorer 6 on Microsoft Windows Server 2003 for Itanium-based Systems (including Service Pack 1) Internet Explorer 6 on Microsoft Windows Server 2003 x64 Edition Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Millennium Edition Internet Explorer 6 Service Pack 1 on Microsoft Windows 98, on Microsoft Windows 98 SE, and Millennium Edition Category: UPDATE Severity: HIGH Attention: Windows System Administrators, Desktop Support Personnel, Users of above-listed version of MS Internet Explore |
Attention: Windows System Administrators, Desktop Support Personnel, Users of above-listed version of MS Internet Explorer
Summary: On November 21 2005 Microsoft released security advisory 911302 in response to publicly-released Proof of Concept (PoC) Code that demonstrates a method of exploit on **fully-patched** windows systems that utilize the popular Internet Explorer web browser. Advisory 911302 details the mitigating factors of the vulnerability and also offers some suggested work-arounds to minimize the possibility of exposure (at the time of this writing a patch for the vulnerability has yet to be released).
Recommended Actions: System Administrators and support personnel are encouraged to read advisory 911302 (link provided below) and to frequently recheck it for updates and/or the release of software updates (patches) from the vendor.
ITS Actions: ALARM will continue to release updates as new information/recommended actions become available.
Resources:
Microsoft Security Advisory 911302:
http://www.microsoft.com/technet/security/advisory/911302.mspx