Microsoft patches IE with record-setting updates to prep browser for Pwn2Own
IE9, IE10 face hackers in three weeks when $175,000 is up for grabs at annual contest
Computerworld - Microsoft this week patched 14 vulnerabilities in Internet Explorer (IE), preparing the browser for its time as a target early next month at the annual Pwn2Own hacking contest.
On Tuesday, Microsoft patched 57 vulnerabilities, including 14 affecting IE that were delivered in two separate security updates. One of those updates, MS13-009, fixed 13 flaws, a dozen of them judged "critical," the company's most serious threat rating. The second update, MS13-010, patched a single vulnerability. That bug was also pegged critical.
IE9 and IE10 will face Pwn2Own hackers starting March 6 at the CanSecWest security conference in Vancouver, British Columbia. The first researcher to successfully demonstrate an exploit of one or more previously-unknown vulnerabilities in IE9 on Windows 7 will take home a $75,000 cash prize. The first who takes down IE10, Microsoft's newest browser, running on Windows 8, will earn an even $100,000.
Eleven of the 13 vulnerabilities patched in MS13-009 were rated critical for IE9 on Windows 7, while four were tagged the same for IE10 on Windows 8. The one bug in MS13-010 was labeled critical for both browsers.
Microsoft said that all the critical vulnerabilities could be exploited by attackers to hijack a Windows PC. If they had gone unpatched, researchers would have been able to use them at Pwn2Own.
Andrew Storms, director of security operations at nCircle Security, noted the large number of IE vulnerabilities patched this week -- the most in at least six years. "It's a big clearing of the backlog," said Storms.
Another unusual aspect of the IE patches was that they came in more than one update, which Microsoft designates as "bulletins." This was the first month in Storms' memory that Microsoft had issued two IE bulletins simultaneously. Typically, it bundles all patches into one update.
Storms suspected the reason stemmed from Microsoft's internal organization. "I'm guessing the Office team probably created the VML patch," he said, referring to MS13-010, the one-patch update that fixed a flaw in Vector Markup Language (VML).
While MS13-010 patched IE6, IE7, IE8, IE9 and IE10 to fix the VML bug, the image format originated with Microsoft's Office suite, where it remains in wide use. It's supported by IE so that websites and Web apps using the format can be properly rendered. Microsoft has pushed Web developers to use SVG (Scalable Vector Graphics) instead, and has officially made VML obsolete -- although still supported in legacy modes -- in IE10.
If past practice holds, other browser makers will also update their applications before Pwn2Own. Mozilla, for instance, will ship Firefox 19 next Tuesday, Feb. 19. And while Google does not adhere to a regular update schedule for Chrome -- unlike Microsoft and Mozilla -- it will probably patch before the contest as well.
Pwn2Own will award prizes of $100,000 to the first researcher to crack Chrome on Windows 7, and $60,000 to the first to hack Firefox on that same OS.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer, or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@ix.netcom.com.
Security alert
- Apple fixes irritating Mountain Lion bugs, firms up Java defenses
- Popular home routers contain critical security vulnerabilities
- IT security managers too focused on compliance, experts say
- Microsoft patches IE with record-setting updates to prep browser for Pwn2Own
- Adobe releases emergency Flash fixes for two zero-day bugs
- 'Andyhave3cats' is a better password than 'Shehave3cats,' study finds
- 'Bob' outsources tech job to China; watches cat videos at work
- Oracle rushes patch to quash critical Java bugs
- Project Blitzkrieg e-banking heist is a credible threat, McAfee says
- Adobe drags Google into Microsoft's Patch Tuesday
Read more about Malware and Vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Security for Virtualization Learn more.
- When Malware Goes Mobile: Causes, Outcomes and Cures Cybercriminals are increasingly setting their sights on smartphones and other mobile devices. Learn about platform-specific policies and strategies you can employ to protect...
- Top Three Reasons Why Customers Deploy EMC VNX with EMC VPLEX What if you could build a cost effective, continuously available storage infrastructure? Learn the top reasons users are deploying EMC VNX with EMC...
- Clearing the Clouds for Midmarket Businesses The 10-point checklist included in this expert brief has been developed to help small and midsize businesses select the cloud model and cloud...
- Virtustream (Vayence) video taking a 3000-Seat SAP Environment to the Cloud How can public cloud services help your organization reduce costs and increase security for your mission
- Williams & Fudge on Transforming IT with EMC Watch Williams & Fudge Data Center Director Phillip Reynolds discuss why this accounts receivable management firm turned to EMC. All Malware and Vulnerabilities White Papers | Webcasts
