Originally published July 6, 2009 at 2:13 PM | Page modified July 6, 2009 at 2:55 PM
Comments (0)
E-mail article
Print
Share
Microsoft warns of serious computer security hole
Microsoft Corp. has taken the rare step of warning about a serious computer security vulnerability it hasn't fixed yet.
AP Technology Writer
Microsoft Corp. has taken the rare step of warning about a serious computer security vulnerability it hasn't fixed yet.
The vulnerability disclosed Monday affects Internet Explorer users whose computers run the Windows XP or Windows Server 2003 operating software.
It can allow hackers to remotely take control of victims' machines. The victims don't need to do anything to get infected except visit a Web site that's been hacked.
Security experts say criminals have been attacking the vulnerability for nearly a week. Thousands of sites have been hacked to serve up malicious software that exploits the vulnerability. People are drawn to these sites by clicking a link in spam e-mail.
The so-called "zero day" vulnerability disclosed by Microsoft affects a part of its software used to play video. The problem arises from the way the software interacts with Internet Explorer, which opens a hole for hackers to tunnel into.
Microsoft urged vulnerable users to disable the problematic part of its software, which can be done from Microsoft's Web site, while the company works on a "patch" - or software fix - for the problem.
Microsoft rarely departs from its practice of issuing security updates the second Tuesday of each month. When the Redmond, Wash.-based company does issue security reminders at other times, it's because the vulnerabilities are very serious.
A recent example was the emergency patch Microsoft issued in October for a vulnerability that criminals exploited to infect millions of PCs with the Conficker worm. While initially feared as an all-powerful doomsday device, that network of infected machines was eventually used for mundane moneymaking schemes like sending spam and pushing fake antivirus software.
---
On the Net:
Microsoft support page:
http://tinyurl.com/kwh8ls
Copyright © The Seattle Times Company
![]()
Tech frenzy over mobile at world trade show
Microsoft names Satya Nadella to run server/tools unit
Brier Dudley: HP to reshape its computer business with own operating system

- Lakewood cop accused of embezzling $150K meant for slain officers' families
- 3 big health insurers stockpile $2.4 billion as rates keep rising
- Agency set to investigate handling of 911 call about Josh Powell
- Quick decisions: How Washington hired its new football staff
- Historic day for gay marriage as another fight looms
- Justin Wilcox's versatile defensive style is the right fit for Huskies | Jerry Brewer
- Social worker recounts minutes before Powell fire
- It's Terrence Time: Enigmatic Ross leads Huskies
- $25B settlement reached over foreclosure abuses
- Club promoter convicted in brutal 2010 murder of Des Moines prostitute
- Gay-marriage bill passes House, awaits Gregoire's signature
491 - Wanted in Seattle classrooms: more teachers of color
375 - Council members get briefing on arena proposal, minus details
273 - AP Source: Obama to change birth control rule
267 - 3 big health insurers stockpile $2.4 billion as rates keep rising
245 - Oregon live game thread
155 - Pac-12 picks ... including the UW game
140 - Worker: Josh Powell told son he had 'surprise'
108 - Rough road again
102 - USA Today further spells out how Mariners, handful of clubs next in line for huge cash windfall
74
- Wanted in Seattle classrooms: more teachers of color
- State Medicaid program to stop paying for unneeded ER visits
- 3 big health insurers stockpile $2.4 billion as rates keep rising
- Economy, blogs give survivalists new reason to look to Northwest
- State's share of mortgage settlement: $648 million
- One man's audacious pursuit of sailing history
- Darren Berg gets 18-year sentence for Ponzi scheme
- Bellevue College adds a third bachelor's degree program
- $25B settlement reached over foreclosure abuses
- 'Gauguin and Polynesia': dazzling mix-and-match | Art review
