Microsoft acknowledges zero day vulnerability in all versions of Internet Explorer

Shawn Knight

Posts: 15,291   +192
Staff member

microsoft browser ie zero day vulnerability

Microsoft on Saturday issued a security advisory for a vulnerability in Internet Explorer that could allow for remote code execution. The Redmond-based company said they are aware of limited, targeted attacks that attempt to exploit a vulnerability in versions 6 through 11 of Internet Explorer.

According to security firm Fire Eye, however, IE versions 9, 10 and 11 are the only ones being actively targeted at this time. Even still, it’s a serious threat as the vulnerable versions represent about a quarter of the total browser market, Fire Eye said.

The firm further points out that the exploit leverages a previously unknown use-after-free vulnerability as well as a well-known Flash exploitation technique to achieve arbitrary memory access and bypass Windows’ ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) protections.

Microsoft claims an attacker could host a specially crafted website that is designed to exploit this vulnerability then convince a user to view the website. If successful in infecting a system, an attacker could gain the same user rights as the current user.

Once an investigation is complete, Microsoft said they will take the appropriate action to protect customers. That may include providing a solution through their monthly security update release process or an out-of-cycle security update.

Until then, it would be wise to avoid using Internet Explorer completely and stick with other popular alternatives such as Chrome, Firefox or Safari.

Permalink to story.

 
"Until then, it would be wise to avoid using Internet Explorer completely and stick with other popular alternatives such as Chrome, Firefox or Safari."
If I had a dollar for every time I've heard that over the years
 
If I had a dollar for every time I've heard that over the years
Yeah, as if the other browsers never have problems. At least you are not being advised "Don't use the Internet because there is a chance you can be infected". Which by the way is a more realistic probability, than being effected by this vulnerability.
 
Sad part is that there is a high probability that someone may become infected at my workplace unless people are warned about it, and because of the use of ActiveX controls and browser specific programming, almost the entire company cannot avoid using Internet Explorer without taking a productivity or financial hit.
 
If I had a dollar for every time I've heard that over the years
Yeah, as if the other browsers never have problems. At least you are not being advised "Don't use the Internet because there is a chance you can be infected". Which by the way is a more realistic probability, than being effected by this vulnerability.

Internet explorer is the worst browser out of the lot... I prefer chrome its fast, sleek, tiny UI plus its not like explorer just left for dead for a few good years xD

Internet explorer was awesome back in the day but today I think its terrible...
 
With the addition of 64 bit browsers, waterfox, cyberfox, and pale moon to name a few (my system is win 7 64 bit) I haven't used ie for years. Feel bad for workstation users though, as they may have no other choices, although I have the choice of ie, chrome or firefox at work, you know I'm not using ie.
 
The advisory is here

Workarounds are available, including this:
a major offender is the VRMLsupport which can be disabled:
Click Start, click Run, type
"%SystemRoot%\System32\regsvr32.exe" -u "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll",

and then click OK.
To my knowledge, few websites use this stuff anyway.
 
Yeah, as if the other browsers never have problems. At least you are not being advised "Don't use the Internet because there is a chance you can be infected". Which by the way is a more realistic probability, than being effected by this vulnerability.
True. No harm intended, I just like to throw punches when something is down for the count lol
 
Back