eEye Digital Security Releases Temporary Patch to Protect Against Critical Internet Explorer Vulnerability
eEye Digital Security has released multiple forms of protection to address a highly critical exploit circulating via a flaw in Microsoft's Internet Explorer (IE) Web browser. The vulnerability, which affects Internet Explorer versions 5.01 SP4 through 6.0 SP1, allows for remote code execution on the target system. eEye's award-winning HIPS solution, Blink, provides proactive protection against this flaw without the need for a software patch.
Key Takeaways:
- eEye confirmed that Blink, its endpoint intrusion prevention solution, provides proactive protection against the critical Internet Explorer vulnerability.
- A temporary patch has been released for organizations unable to deploy Blink, which can be downloaded at http://www.eEye.com/html/research/alerts/AL20060324.html.
- The vulnerability affects Internet Explorer versions 5.01 SP4 through 6.0 SP1 and allows for remote code execution on the target system.
- System administrators should disable Active Scripting from within Internet Explorer to protect systems against this attack.
- Unlike signature-based solutions, current Blink customers are not required to do anything to realize protection from this flaw, as no updates or policy changes are required.
- Blink allows organizations to defer patching vulnerable machines until regularly scheduled maintenance cycles, saving millions of dollars in business disruption and IT resource drain.
- eEye's integrated family of vulnerability management solutions includes Retina Network Security Scanner, REM Security Management Console, Iris Network Traffic Analyzer, and SecureIIS Web Server Protection.
Statistics:
- 100% protection against the critical Internet Explorer vulnerability provided by Blink.
- Zero downtime or impact to operations for enterprises using Blink.
- 8,500 corporate and government deployments worldwide of eEye's vulnerability assessment and prevention technology.
- 5 years of expertise in the discovery of critical vulnerabilities in various platforms and applications, including the Sasser, Witty, and Code Red worms.
- 1000s of other important discoveries made by eEye over the last 5 years.
Sources:
- eEye Digital Security press release, "eEye Releases Temporary Software Patch to Protect Against Zero-Day Flaw," 24 March 2006.
- Microsoft Security Advisory 917077.
- eEye Digital Security Website: http://www.eEye.com/
- eEye Digital Security Blink product page: http://www.eEye.com/Blink.