UPDATED 19:57 EDT / JANUARY 19 2020

SECURITY

Internet Explorer vulnerability under attack, but a fix is weeks away

A new vulnerability discovered in Internet Explorer is being exploited in the wild, but though Microsoft Corp. is promising a fix, it may be weeks away.

The vulnerability was disclosed by Microsoft Friday and was thought serious enough that it gained the attention of the U.S. Department Homeland Security Cybersecurity and Infrastructure Agency as well.

The critical vulnerability affects Internet Explorer 9, 10, and 11 on Windows 7, 8.1, RT 8.1, 10, Server 2008, 2008 R2, Server 2012, Server 2016 and Sever 2019. The remote code execution vulnerability related to how the scripting engine in IE handles objects, allowing an attacker to corrupt memory to run arbitrary code.

To exploit the vulnerability, an attacker can use a crafted web page or HTML document that can trigger IE to exploit the vulnerability. The extent of how far it has been exploited was not made clear with Microsoft saying that it’s “aware of limited targeted attacks.”

The advice from CISA, at least, is to not use IE, which, given that it has now been five years since Microsoft replaced it with Edge, would seem logical. But it’s not always possible. According to Statcounter, IE still holds a 3.56% market share of desktop browsers as of December, down from 5.4% a year before. But those holdouts exist for a reason, most commonly because legacy pages and related services require it. Those aren’t necessarily online web pages but intranet pages that have been set up to work with internal systems.

IE was famous for that, with IE 6 in particular not built on web standards and hence pages designed for the version would not work with other browsers. The later versions of IE still offered backwards compatibility through their capability mode. Over time, intranet pages have been redesigned, but it’s a process that takes time.

How many pages use IE is difficult to estimate. “There is no particular sector, we find IE used in administration as well as in health or industry for example,” Victor Poitevin, digital manager at cybersecurity firm Stormshield, wrote in July. “It is complicated to estimate the percentage of businesses that use IE. It concerns applications used internally…. We are talking about internal software, which has very often been customized for the company: intranet, accounting software, stock management software, etc.”

Image: Maxpixel

A message from John Furrier, co-founder of SiliconANGLE:

Show your support for our mission by joining our Cube Club and Cube Event Community of experts. Join the community that includes Amazon Web Services and Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger and many more luminaries and experts.

Join Our Community 

Click here to join the free and open Startup Showcase event.

“TheCUBE is part of re:Invent, you know, you guys really are a part of the event and we really appreciate your coming here and I know people appreciate the content you create as well” – Andy Jassy

We really want to hear from you, and we’re looking forward to seeing you at the event and in theCUBE Club.

Click here to join the free and open Startup Showcase event.