Unpatched Microsoft Internet Explorer vulnerability being actively exploited

Graham Cluley
Graham Cluley
@

 @grahamcluley.com
 @[email protected]

Critical

As many of you who follow the security scene will know, Microsoft released an advisory about a zero-day vulnerability in the Internet Explorer web browser a couple of days ago.

Sophos published its own analysis of the severity of the vulnerability that I would recommend you read if you haven’t already done so.

The bad news is that there isn’t an official fix for this vulnerability from Microsoft yet, and we are seeing real in-the-wild instances of websites being struck by SQL injection attacks that then serve up the exploit.

Sign up to our free newsletter.
Security news, advice, and tips.

Fraser Howard goes into greater detail about this problem on the SophosLabs blog, explaining how the analysts in our research labs have developed protection against the current wave of attacks and how we have prepared proactive defences what may crop up in the future too.

The latest Sophos Security Threat Report discussed the rising tide of SQL injection attacks and the threat posed by hacked websites (there have been three times more infected webpages discovered during 2008 than in 2007, with one new victim found every 4.5 seconds).

If you haven’t yet managed to convince your bosses of the needs for comprehensive protection against web-borne threats, maybe now is the time to do it.


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and is the co-host of the popular "The AI Fix" and "Smashing Security" podcasts. Follow him on Bluesky and Mastodon, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.