“Microsoft confirmed Thursday that the createTextRange security flaw in Internet Explorer will be among those addressed in its monthly patch rollout April 11. In all, the company said on its TechNet site, customers can expect five updates for Microsoft Windows and Microsoft Office — at least one of them critical.”
There is still yet to be a patch released by Microsoft and the only workaround for IE users is to disable active scripting, which by the way breaks some web sites functionality (which is ironic because Active scripting (ActiveX) is why most people are forced to use IE). Here’s a tip, use Firefox. Of course then come the arguments such as how to control Firefox with group policy, or what to do with applications that only work with IE. Check out the WetDog project for group policy control over Firefox. If you have applications that require IE consider creating a shortcut that uses IE to access that application and let users do what they do best, click. Most organizations do not do this because they do not believe that IE vulnerabilities are a problem:
But now, she said, borrowing a phrase from the Star Trek universe, “the shields are holding.”
If a Windows box gets rooted with IE exploit on the Internet, will anybody notice?
.comFull Article



