

A new vulnerability discovered in Internet Explorer is being exploited in the wild, but though Microsoft Corp. is promising a fix, it may be weeks away.
The vulnerability was disclosed by Microsoft Friday and was thought serious enough that it gained the attention of the U.S. Department Homeland Security Cybersecurity and Infrastructure Agency as well.
The critical vulnerability affects Internet Explorer 9, 10, and 11 on Windows 7, 8.1, RT 8.1, 10, Server 2008, 2008 R2, Server 2012, Server 2016 and Sever 2019. The remote code execution vulnerability related to how the scripting engine in IE handles objects, allowing an attacker to corrupt memory to run arbitrary code.
To exploit the vulnerability, an attacker can use a crafted web page or HTML document that can trigger IE to exploit the vulnerability. The extent of how far it has been exploited was not made clear with Microsoft saying that it’s “aware of limited targeted attacks.”
The advice from CISA, at least, is to not use IE, which, given that it has now been five years since Microsoft replaced it with Edge, would seem logical. But it’s not always possible. According to Statcounter, IE still holds a 3.56% market share of desktop browsers as of December, down from 5.4% a year before. But those holdouts exist for a reason, most commonly because legacy pages and related services require it. Those aren’t necessarily online web pages but intranet pages that have been set up to work with internal systems.
IE was famous for that, with IE 6 in particular not built on web standards and hence pages designed for the version would not work with other browsers. The later versions of IE still offered backwards compatibility through their capability mode. Over time, intranet pages have been redesigned, but it’s a process that takes time.
How many pages use IE is difficult to estimate. “There is no particular sector, we find IE used in administration as well as in health or industry for example,” Victor Poitevin, digital manager at cybersecurity firm Stormshield, wrote in July. “It is complicated to estimate the percentage of businesses that use IE. It concerns applications used internally…. We are talking about internal software, which has very often been customized for the company: intranet, accounting software, stock management software, etc.”
Support our open free content by sharing and engaging with our content and community.
Where Technology Leaders Connect, Share Intelligence & Create Opportunities
SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.