Microsoft to update IE after bugs found
Microsoft Corp. is readying an update to Internet Explorer (IE) following the recent discovery of two unpatched IE vulnerabilities, including one bug that could allow attackers to seize control of a victim's PC. "We're working on an update to Internet Explorer and that update is currently in our testing process and could come out as early as April," said Stephen Toulouse, a security program manager with Microsoft's security response center. "However, there's no firm date."
The most significant of the two vulnerabilities was discovered earlier this month by Web developer Jeffrey van der Stad. He claims to have uncovered a way for attackers to trick IE into executing HTA (HTML application) files without the user's permission. HTA is a Microsoft-created format that is used to create HTML-based applications.(continue at source)








