The bad part is the exploits were released so quickly, most people haven't patched them yet. |
The flaw can be exploited if the user opens a wrong file or goes to a wrong Web site. Then the attacker can execute code as the user, who is viewing the file or Web site. |
The race is definitely going to be won by the exploit writers, because they're going to be able to publish an exploit in the next couple of days, ... It's such a glaring bug, I don't know how anybody else didn't discover it. |
This is the type of vulnerability that's been exploited many times, and those two worms are the biggest examples because they had the biggest impact, |
We are definitely going to see dangerous exploits for it because it's not really technically challenging to write the exploit code. |
We have a good working relationship with Microsoft. We may disagree on a lot of things, especially how long it takes them to come up with a patch, but we agree on the most important thing, which is keeping customers protected. |
Yes, there is the marketing side of things like [developing] the IE patch. But at the end of the day, we put a patch out there to help. It's not like we did something bad to get this attention. |
You have to wonder why it took more than 220 days to create that patch if they missed these flaws. |