Skip to main content
BBC NEWS / TECHNOLOGY
Graphics VersionBBC Sport Home
News Front Page | Africa | Americas | Asia-Pacific | Europe | Middle East | South Asia | UK | Business | Health | Science & Environment | Technology | Entertainment | Also in the news | Have Your Say |
Friday, 25 August 2006, 10:05 GMT 11:05 UK

Microsoft fixes flawed bug patch

Workers looking at computer screen, Eyewire Microsoft has re-issued a security update after it was discovered that the patch introduced a bug of its own.

The original patch was issued to close a loophole in Internet Explorer that could be used to hijack a PC.

This patch was due to be updated because, in some circumstances, it caused Microsoft's browser to crash.

Solving the problem became more acute when security researchers discovered that the crash could also be exploited to take control of a PC.

Update alert

The problems revolve around the MS06-042 security patch for Internet Explorer that Microsoft originally released on 8 August.

This update had Microsoft's highest "critical" rating and fixed eight vulnerabilities in the popular browser.

Soon after releasing the update Microsoft received reports that, in some circumstances, it was causing Internet Explorer to crash.

The software giant pledged to fix the update but its efforts became more urgent when security firm EEye Digital Security discovered that the crash circumstances could be exploited to run malicious code on that machine.

The re-issued patch was delayed because of incompatibilities with the distribution tools some firms were using to install it.

Microsoft said the security problem introduced by its update would affect the relatively small number of users running Windows 2000.

It said that group of people were most likely to be using the crash-prone version of Internet Explorer as that was the most recent version of the browser for that operating system. The crashes were seen on machine using Internet Explorer 6 with the Service Pack 1 update installed.



E-mail this to a friend
Related to this story:
Hackers target latest Windows fix (16 Aug 06 |  Technology )
User pain may mean Windows cracks (21 Aug 06 |  Technology )
Microsoft warning on online games (15 Aug 06 |  Technology )
Official warning on Windows bugs (11 Aug 06 |  Technology )
Hijacked handheld turns data spy (09 Aug 06 |  Technology )
Poisoned PowerPoint attacks users (20 Jul 06 |  Technology )

RELATED INTERNET LINKS
Microsoft Security Response Center blog
MS06-042 security update
Microsoft security advice on patch problems
EEye Digital Security
The BBC is not responsible for the content of external internet sites



SEARCH BBC NEWS: 

News Front Page | Africa | Americas | Asia-Pacific | Europe | Middle East | South Asia | UK | Business | Health | Science & Environment | Technology | Entertainment | Also in the news | Have Your Say |

NewsWatch | Notes | Contact us | About BBC News | Profiles | History

^ Back to top | BBC Sport Home | BBC Homepage | Contact us | Help | ©