Microsoft Security Advisory 2847140 for Internet Explorer 8: threats around malicious websites.



The vulnerability that affects Internet Explorer 8, allows remote code execution if users browse to a malicious website with an affected browser. This attack is possible if an attacker convinces someone to click a link in an email or instant message.
Therefore pending the release of a security update to address this issue, Microsoft
encourages you to upgrade to Internet Explorer 9 and 10. In addition customers using affected versions of Internet Explorer are also encouraged deploying the following workarounds:
  • ‘’Set Internet and local intranet security zone settings to "High" to block ActiveX Controls and Active Scripting in these zones this will help prevent exploitation but may affect usability; therefore, trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.
  • Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and local intranet security zones
    This will help prevent exploitation but can affect usability, so trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.’’
And finally you are also invited to exercise caution when visiting websites and avoid clicking suspicious links, or opening email messages from unfamiliar senders.

Popular Posts