US-Cert has issued a new Technical Cyber Security Alert - TA10-089A:
Microsoft Internet Explorer VulnerabilitiesOriginal release date: March 30, 2010
Last revised: --
- Microsoft Internet Explorer
Microsoft has released out-of-band updates to address critical vulnerabilities in Internet Explorer.
Microsoft has released updates for multiple vulnerabilities in Internet Explorer, including the vulnerability detailed in Microsoft Security Advisory (981374) and US-CERT Vulnerability Note VU#744549.
By convincing a user to view a specially crafted HTML document or Microsoft Office document, an attacker may be able to execute arbitrary code with the privileges of the user.
Microsoft has released updates to address these vulnerabilities. Please see Microsoft Security Bulletin MS10-018 for more information.
Microsoft has provided workarounds for some of the vulnerabilities in MS10-018.
- Microsoft Security Bulletin MS10-018 - <http://www.microsoft.com/technet/security/bulletin/ms10-018.mspx>
- Microsoft Security Advisory (981374) - <http://www.microsoft.com/technet/security/advisory/981374.mspx>
- Microsoft Internet Explorer iepeers.dll use-after-free vulnerability - <http://www.kb.cert.org/vuls/id/744549>