Disabling IE’s Flash plug-in will stop the bug cold
Disabling IE’s Flash plug-in will stop the bug cold, FireEye says — although that will also render your browser powerless to play Flash videos and games.
There are other, more technical ways around the exploit as well. You can install a piece of software called the Enhanced Mitigation Experience Toolkit (EMET) and configure it for Internet Explorer, Microsoft recommends. That will let you browse without altering your web experience much. Be sure to use EMET 4.1 since it’s automatically configured to protect IE.
Separate from Protected Mode, IE has other layers of security, including sliding settings for security zones, which will block malicious software from hijacking your PC if they’re set to high. It will, however, make using some websites (such as order forms) more difficult.
Microsoft is expected to release a patch for the flaw soon — either in the company’s next “Patch Tuesday” update, due May 13, or in an off-schedule patch specifically for this issue. It’s unclear if Windows XP will get the patch; support for the OS officially ended in April, but some large enterprise customers are continuing to get software updates.