Microsoft Plugs IE Hole
7 Comments
Microsoft is expected to release an out of cycle patch to bring to an end to the vulnerability that led to the Download.Ject attacks in June. The attack, called Download.Ject, exploits known flaws in Internet Information Services (IIS) and Internet Explorer whereby users become silently infected with arbitrary code embedded in Web pages. Once installed, the code uploads malware and begins to log keystrokes to obtain personal information such as passwords.