"The flaw is remotely exploitable," said Mike Puterbaugh, eEye's director of product management.
Although eEye has notified Microsoft of the bug -- and Microsoft has confirmed receipt of the report -- no patch is available. According to eEye, that's not unusual: on average, Microsoft has taken 132 days to patch holes that the Aliso Viejo, Calif.-based security vendor has reported since February 2004.
eEye takes the unique step of logging its reports to Microsoft, then showing the number of days since the vulnerability was confirmed by the Redmond company. After 60 days, it considers a patch "overdue."
Internet Explorer, says eEye, has at least five other critical, but unpatched, vulnerabilities, including ones reported 15, 46, 129, 134, and 171 days ago.
Microsoft has been patching IE regularly, but is having trouble keeping up with the browser's vulnerabilities. In August, it fixed three bugs in the browser, and since the first of the year, has patched IE five out of nine months.
BP seeking Regional Desktop Coordinator in Houston, TX
Lowes seeking DC Systems Technician I in Lebanon, OR
INVIA Medical Imaging Solutions seeking Software Engineer in Ann Arbor, MI
Citrus Community College seeking Programmer Analyst II in Glendora, CA
City of Westland seeking MIS Director in Westland, MI
For more great jobs, career-related news, features and services, please visit our Career Center.
Web Reputation Filters Battle the Latest Web Malware Threats
IronPort Web Reputation Filters™ are designed to combat the dynamic nature of malware. Today’s threats are no longer found as an email attachment. Instead, they are well orchestrated – utilizing social engineering techniques and target legitimate websites. As the first line of malware defense, IronPort Web Reputation Filters analyze more than 5 billion Web transactions daily – blocking up to 70 percent of malware at the connection level, prior to signature scanning. By leveraging its global footprint of URL traffic data IronPort’s Web reputation system is able to offer an industry-leading 60 percent higher malware catch rate than traditional signature scanners.

NOTE: Offer valid for U.S., U.S. possessions, & Canada only