Microsoft Corp. today issued an emergency software update to plug a critical security hole in its Windows operating system. The free update is available either from the Microsoft Update site or via the company's automatic updates feature. Alternatively, Windows users can download and manually install the standalone patch directly from the Microsoft security advisory.
Windows users should install this update immediately, as an increasing number of criminal groups are targeting one of the vulnerabilities fixed by this patch to silently install software when users visit a malicious Web site or open a specially crafted e-mail.
Microsoft had been slated to release the update a week from today, but issued the fix earlier due to a marked increase in the number of attackers currently exploiting the flaw. In addition, today's patch also fixes six other security holes present within nearly all versions of Windows.
This is the third time since January 2006 that Microsoft has deviated from its monthly patch cycle to plug security holes that hackers were actively exploiting. The company typically issues patches on the second Tuesday of each month.
[ Microsoft Security Bulletin MS07-017 ]