, SecurityFocus 2006-08-22
UPDATE: Microsoft continued to work on Tuesday to create a fix for an exploitable flaw introduced by the company's latest security update to Internet Explorer.
Expand all |
Post comment
|
Microsoft patch opens users to attack
, SecurityFocus 2006-08-22 UPDATE: Microsoft continued to work on Tuesday to create a fix for an exploitable flaw introduced by the company's latest security update to Internet Explorer.
Expand all |
Post comment
|
|
|
Privacy Statement |
There's a perfectly good excuse not to patch -- you go from dealing with vulnerabilities where the amount of in-the-wild knowledge is low to this issue, which is so trivially exploitable and easily identified that someone at Microsoft needs a good slap in the face.
Also, Microsoft chose NOT to communicate this issue to the public. They were going to continue passing off this issue as a "crash", even when they knew otherwise. That is MISREPRESENTATION, and it's what Microsoft has been hammered on by myself and others before. Further, when eEye did disclose the issue, Microsoft accused them of being "irresponsible".
I don't know how you get anything positive about this for Microsoft. MS06-042 and the resultant handling was a complete f---up on all counts -- one that reminds me of the 2000-era Microsoft. Keep in mind that they've had major QA problems with three patches in the last four cycles, now: MS06-042, MS06-040 and MS06-015.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/11408/34020#34020