You all seem to be missing the point here. It was understood in May that there was a flaw in IE. The worst known vulnerability in that flaw was instability of the browser, considered to be a very low priority, and perhaps not even worth patching in older systems.
This new proof of concept is the first notification to Microsoft that there was any vulnerability other than the stability issue. It is generally considered poor practice to release an exploit prior to contacting the company about the existence of the vulnerability.
This new proof of concept is the first notification to Microsoft that there was any vulnerability other than the stability issue. It is generally considered poor practice to release an exploit prior to contacting the company about the existence of the vulnerability.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/newsbriefs/58/219#219