B
Bill Sanderson MVP
http://www.microsoft.com/technet/security/advisory/917077.mspx
I think this is worth bringing to the attention of readers in this group for
a couple of reasons:
1) to understand that the statistical effect of the attack is being
monitored carefully--lots of eyes are on this, and some are being more
careful about what they report than others are.
2) That we all understand that the fix for this will be part of a cumulative
security update for IE6. This update will also include the following fix:
http://support.microsoft.com/kb/912945
This change in IE behavior with regards to ActiveX controls may have
substantial impact in some corporate settings--so you need to be prepared
for this change.
3) To understand that IE7 beta2 is immune to this one already. This beta
does have one reported (and blogged about) installation issue that I haven't
seen myself--but otherwise it is an easy install and just as easy uninstall
back to IE6. A reboot is required. Updates to it are being distributed via
WSUS, if you as the administrator enable them--just as you did with Windows
Defender definitions.
--
I think this is worth bringing to the attention of readers in this group for
a couple of reasons:
1) to understand that the statistical effect of the attack is being
monitored carefully--lots of eyes are on this, and some are being more
careful about what they report than others are.
2) That we all understand that the fix for this will be part of a cumulative
security update for IE6. This update will also include the following fix:
http://support.microsoft.com/kb/912945
This change in IE behavior with regards to ActiveX controls may have
substantial impact in some corporate settings--so you need to be prepared
for this change.
3) To understand that IE7 beta2 is immune to this one already. This beta
does have one reported (and blogged about) installation issue that I haven't
seen myself--but otherwise it is an easy install and just as easy uninstall
back to IE6. A reboot is required. Updates to it are being distributed via
WSUS, if you as the administrator enable them--just as you did with Windows
Defender definitions.
--