New super patch for IE fixes six new flaws

InfoWorld | at | by Mike

Microsoft late Thursday issued a cumulative patch for its Internet Explorer Web browser that also fixes six new vulnerabilities, the most serious of which could enable an attacker to take control over a user's system, Microsoft said. A cumulative patch is a patch that includes all previously released fixes for a software product. The six newly patched vulnerabilities exist in various parts of Internet Explorer and mainly put client systems at risk, but Microsoft deems the super patch "critical" for Internet and Intranet servers too.

In addition to fixing the vulnerabilities, the patch package also permanently disables two vulnerable ActiveX controls, one linked to the MSN chat application and one to a feature for terminal services sessions, Microsoft said. ActiveX controls are small programs designed to perform a single task.