Microsoft issues ‘out-of-band’ patch for IE’s Visual Studio vulnerability
In its first 'out-of-band' security update release this year, Microsoft Tuesday announced patches to address a critical vulnerability in the Internet Explorer (IE) Web browser's Visual Studio Active Template Library (ATL) that facilitated remote code execution.
Microsoft, which generally sticks to its 'once-a-month security fix' schedule for the convenience of IT professionals who test and deploy the patches, releases its 'out-of- band' updates only when it considers a flaw as critical enough in terms of being exploited remotely.
In the case of the vulnerability, however, the users can make themselves susceptible to an attack by merely viewing a malicious Web page.
However, with a Microsoft spokesman saying that the users going in for automatic updates are largely protected against such flaws, it becomes apparent that the company's 'emergency security fix' move is essentially a part of its so-called new defense-in-depth technology - designed for protecting IE users from potential future attacks using the ATL vulnerabilities.
A part of the Microsoft Security Response Center Team's statement about the emergency patch went thus: "The vulnerability that we addressed with Microsoft Security Bulletin MS09-032 was a result of the ATL issue. We are releasing our guidance and updates outside of our regular monthly release cycle because we believe that there is a greater risk to customer safety from broader disclosure of this issue if we wait until our next scheduled release."