Advisories!: Update NOW to avoid the CoolWebSearch Zero Day Exploit
Corrine writes "The latest second Tuesday security update from Microsoft reads in part:
Microsoft Security Bulletin MS05-054
Cumulative Security Update for Internet Explorer (905915)
Published: December 13, 2005
Version: 1.0
Summary
Who should read this document: Customers who use Microsoft Windows
Impact of Vulnerability: Remote Code Execution Maximum Severity Rating: Critical
Recommendation: Customers should apply the update immediately.
Security Update Replacement: This update replaces the update that is included with Microsoft Security Bulletin MS05-052. That update is also a cumulative update.
The information that is not provided in the bulletin, however, is that Cumulative Security Update for Internet Explorer (905915) will protect your computer from the latest Cool Web Search (CWS) exploits. These exploits, commonly being referred to as the Zero Day Exploit are so bad they could lead to reimaging an unpatched computer.
There are 100 or so CWS sites that started using the Zero Day Exploit last week in place of the usual chm exploits and other types of scripts. Patch 905915 has been successfully tested against those sites on computers operating Microsoft XP with both service packs, SP1 and SP2.
Update now to prevent the Zero Day Exploit from infecting your PC!
~~~~~~~~~~~~~~~~~
Additional information on this patch is available from Microsoft in the Microsoft Knowledge Base Article at http://support.microsoft.com/kb/905915 .
"
Posted on Wednesday, 14 December 2005 @ 10:19:08 UTC by Paul (2138 reads) [ Trackback ]