Microsoft urges customers to update vulnerable versions of SSL to a newer one that is not susceptible to a recently published exploit called BEAST. BEAST is a Java script that exploits a weakness found when SSL uses block ciphers. Microsoft recommends changing the order in which SSL/TLS negotiates cipher suites. The fix is time consuming and not all browsers – Firefox for instance – support the latest version of the protocol. The vulnerability has been known since 2004, but the consensus was that it couldn’t be exploited.”]

