Woody Leonhard’s no-bull news, tips and help for Windows and Office
RSS icon Email icon Home icon
  • MS-DEFCON 2: Black Tuesday – no need to patch if you don’t use Internet Explorer

    Posted on February 11th, 2009 at 15:51 woody No comments

    Microsoft just released four security bulletins, covering seven separately identified security holes. A couple of them could turn into something nasty, if the bad guys figure out how, but for now if you don’t use Internet Explorer 7, you should be OK.

    Yes, I said IE 7. The patch doesn’t involve IE 6.

    SANS Internet Storm center reports no known exploits for any of the new security bulletins, except the SQL Server fix, MS09-004 / KB 959420. Microsoft only rates that’n as “Important” because “An attacker would need to either authenticate to exploit the vulnerability or take advantage of a SQL injection vulnerability in a Web application that is able to authenticate.”

    No need to patch yet, unless you insist upon using Internet Explorer 7. Let’s sit tight and see what breaks.

    Leave a reply