The Latest in IT Security

Java & IE Patches + Prompts

14
Jan
2013

Microsoft is releasing an out of cycle security update for users of Internet Explorer 6-8.

Advisory_2704220

According to Microsoft: “While we have still seen only a limited number of customers affected by the issue, the potential exists that more customers could be affected in the future.”

Potential indeed – there’s now evidence of this IE vulnerability being incorporated into popular exploit kits such as Blackhole. Be sure to update as soon as possible.

Java: something you should have already updated (if you still use it at all).

Here’s what the CVE-2013-0422 Java (JRE) exploit looked like among our top detections last week.

java0daystats

As you can see, the exploit grew in prevalence, but remains in the middle of the pack. That is because not everybody is running the latest version of Java (7u11), and exploit kits do version checking. Thus, we still see more exploits for older versions of Java. So it’s important to update to the current version!

Additionally, from Oracle: “The fixes in this Alert include a change to the default Java Security Level setting from “Medium” to “High”. With the “High” setting, the user is always prompted before any unsigned Java applet or Java Web Start application is run.”

Here’s what the prompt looks like:

Java_7u11_prompt_unsigned

Here’s the prompt of a self-signed app:

Java_7u11_prompt_signed

Leave a reply


Categories

WEDNESDAY, APRIL 24, 2024
WHITE PAPERS

Mission-Critical Broadband – Why Governments Should Partner with Commercial Operators:
Many governments embrace mobile network operator (MNO) networks as ...

ARA at Scale: How to Choose a Solution That Grows With Your Needs:
Application release automation (ARA) tools enable best practices in...

The Multi-Model Database:
Part of the “new normal” where data and cloud applications are ...

Featured

Archives

Latest Comments