Microsoft Corp issued an interim security update Friday to protect users of its nearly ubiquitous Internet Explorer browsers from a new technique for spreading viruses.
The update does not entirely fix the flaw that makes the spread possible, but it changes settings in Windows operating systems to disable hackers' ability to deliver malicious code with it.
The security measure came in response to last week's discovery of a computer virus designed to steal valuable information like passwords. Though its outbreak was mild, security experts said the technique for spreading it was novel and could be used to send spam or launch broad attacks to cripple the Internet.
Hackers had converted hundreds and possibly thousands of Web sites into virus transmitters by first hiding malicious code using a vulnerability with Microsoft's software for operating Web sites.
A fix for it had been issued in April but was not universally applied.
Two other flaws in Microsoft products allowed hackers to direct Internet Explorer browsers to automatically run the virus when visiting an infected site.
Though one of those flaws remains unfixed, Friday's setting changes thwart any attack by prohibiting a Web application from writing files -- such as the virus code -- onto users' computers.
Stephen Toulouse, a security program manager at Microsoft, said the company still was working on a comprehensive patch to fix vulnerabilities with Internet Explorer, but the settings change should protect users from the immediate threat.
The software update covers Windows XP, Windows Server 2003 and Windows 2000, and Microsoft was working on ones for older systems.
The update will also be included with a major Windows XP upgrade, called Service Pack 2, later this summer.
Toulouse said the new Service Pack will include additional protections.
After installing Friday's update, users should be able to lower their security settings from the "high" one initially recommended as a stopgap, he said.
Russ Cooper, a senior researcher at TruSecure Corp, welcomed Friday's update, but said it should have come sooner than a week.
"It would have taken a couple of hours to put it together as a package, and [the testing] process can take a day or two," Cooper said.
But Toulouse said that given the broad user base for Windows and Internet Explorer, even a problem affecting less than 1 percent of users potentially hurts millions of customers.
He said the settings could potentially affect legitimate applications used internally by Web developers and corporate networks, and special instructions were available to address those cases.
The update will be automatically installed if computers are set to receive it.
It is also available at http://windowsupdate.microsoft.com.
Microsoft shares fell US$0.06 to close at US$28.57 Friday on the NASDAQ Stock Market.
China has claimed a breakthrough in developing homegrown chipmaking equipment, an important step in overcoming US sanctions designed to thwart Beijing’s semiconductor goals. State-linked organizations are advised to use a new laser-based immersion lithography machine with a resolution of 65 nanometers or better, the Chinese Ministry of Industry and Information Technology (MIIT) said in an announcement this month. Although the note does not specify the supplier, the spec marks a significant step up from the previous most advanced indigenous equipment — developed by Shanghai Micro Electronics Equipment Group Co (SMEE, 上海微電子) — which stood at about 90 nanometers. MIIT’s claimed advances last
ISSUES: Gogoro has been struggling with ballooning losses and was recently embroiled in alleged subsidy fraud, using Chinese-made components instead of locally made parts Gogoro Inc (睿能創意), the nation’s biggest electric scooter maker, yesterday said that its chairman and CEO Horace Luke (陸學森) has resigned amid chronic losses and probes into the company’s alleged involvement in subsidy fraud. The board of directors nominated Reuntex Group (潤泰集團) general counsel Tamon Tseng (曾夢達) as the company’s new chairman, Gogoro said in a statement. Ruentex is Gogoro’s biggest stakeholder. Gogoro Taiwan general manager Henry Chiang (姜家煒) is to serve as acting CEO during the interim period, the statement said. Luke’s departure came as a bombshell yesterday. As a company founder, he has played a key role in pushing for the
Taiwan Semiconductor Manufacturing Co (TSMC, 台積電) has appointed Rose Castanares, executive vice president of TSMC Arizona, as president of the subsidiary, which is responsible for carrying out massive investments by the Taiwanese tech giant in the US state, the company said in a statement yesterday. Castanares will succeed Brian Harrison as president of the Arizona subsidiary on Oct. 1 after the incumbent president steps down from the position with a transfer to the Arizona CEO office to serve as an advisor to TSMC Arizona’s chairman, the statement said. According to TSMC, Harrison is scheduled to retire on Dec. 31. Castanares joined TSMC in
EUROPE ON HOLD: Among a flurry of announcements, Intel said it would postpone new factories in Germany and Poland, but remains committed to its US expansion Intel Corp chief executive officer Pat Gelsinger has landed Amazon.com Inc’s Amazon Web Services (AWS) as a customer for the company’s manufacturing business, potentially bringing work to new plants under construction in the US and boosting his efforts to turn around the embattled chipmaker. Intel and AWS are to coinvest in a custom semiconductor for artificial intelligence computing — what is known as a fabric chip — in a “multiyear, multibillion-dollar framework,” Intel said in a statement on Monday. The work would rely on Intel’s 18A process, an advanced chipmaking technology. Intel shares rose more than 8 percent in late trading after the