Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Vulnerability Found in Every Single Version of Internet Explorer  (Read 7012 times)

0 Members and 1 Guest are viewing this topic.

evilfantasy

    Topic Starter
  • Malware Removal Specialist


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Gizmodo: According to a confirmation by Microsoft late last night, a new zero day vulnerability has been found to affect every version of Internet Explorer. In other words—over a quarter of the entire browser market.

Full story: New Vulnerability Found in Every Single Version of Internet Explorer

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #1 on: April 27, 2014, 07:28:08 PM »
Why doesn't MS show the hackers how to write the code? What do they hope to accomplish by releasing this news before they have a patch?
Windows 8 and Windows 10 dual boot with two SSD's

BC_Programmer


    Mastermind
  • Typing is no substitute for thinking.
  • Thanked: 1140
    • Yes
    • Yes
    • BC-Programming.com
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Windows 11
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #2 on: April 27, 2014, 07:59:57 PM »
Oh Look, Flash is involved. Big surprise there.

Since IE 8 and later (at least to my recollection) require confirmation to run any Active Scripting content, so I'm not sure how it would work in IE8 or later given that.
I was trying to dereference Null Pointers before it was cool.

PCdoc



    Hopeful

    Thanked: 32
    • Yes
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 7
....

camerongray



    Expert
  • Thanked: 306
    • Yes
    • Cameron Gray - The Random Rambings of a Computer Geek
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Mac OS

evilfantasy

    Topic Starter
  • Malware Removal Specialist


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #5 on: April 28, 2014, 08:03:54 AM »
It's very convenient that XP just lost support and MS issues a 'severe warning' to almost all XP users. Upgrade or else...

patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #6 on: April 28, 2014, 08:15:41 AM »
So where's the patch ? ?
" Anyone who goes to a psychiatrist should have his head examined. "

evilfantasy

    Topic Starter
  • Malware Removal Specialist


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #7 on: April 28, 2014, 10:33:14 AM »
So far only workarounds (see the Suggested Actions section). There should be an Out-of-Band Patch from Microsoft coming soon through Windows Update. If they wait until the next Patch Tuesday (over 3 weeks away) then I will really question the severity of this threat.

evilfantasy

    Topic Starter
  • Malware Removal Specialist


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #8 on: April 28, 2014, 11:08:40 AM »
I think it just came through.

Security Update for Internet Explorer Flash Player KB2961887

Check Windows Update.

EDIT: I could be wrong. Adobe has released updates for all browsers today so it may just be a normal browser update.
« Last Edit: April 28, 2014, 11:51:52 AM by evilfantasy »

evilfantasy

    Topic Starter
  • Malware Removal Specialist


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #9 on: April 28, 2014, 02:48:15 PM »
OK. It is the patch and is available at the Adobe website and through Windows Update.

Gizmodo: You Can Download Adobe's Patch for the Internet Explorer Flaw Right Now

Flash Player Help: Check if Flash Player is installed on your computer

They also released updates for Firefox, Mozilla, Netscape and Opera today so if you use those browsers I suggest updating them too. Adobe Flash Player for Firefox, Mozilla, Netscape, Opera 13.0.0.206

evilfantasy

    Topic Starter
  • Malware Removal Specialist


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #10 on: May 01, 2014, 12:28:41 PM »
 The Microsoft update is available through Windows Update. Description of the security update for Internet Explorer for systems that have security update 2929437

Applies to

* Internet Explorer 11
* Internet Explorer 10
* Windows Internet Explorer 9
* Windows Internet Explorer 8
* Windows Internet Explorer 7
* Microsoft Internet Explorer 6.0

Despite the scare tactics from Microsoft that XP will remain vulnerable this Out-of-Band update included Windows XP. Out-of-Band Release to Address Microsoft Security Advisory 2963983

Quote from: Dustin C. Childs - TechNet Blog
We have made the decision to issue a security update for Windows XP users. Windows XP is no longer supported by Microsoft, and we continue to encourage customers to migrate to a modern operating system, such as Windows 7 or 8.1. Additionally, customers are encouraged to upgrade to the latest version of Internet Explorer, IE 11.
« Last Edit: May 01, 2014, 01:09:16 PM by evilfantasy »

DaveLembke



    Sage
  • Thanked: 662
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 10
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #11 on: May 01, 2014, 01:33:08 PM »
Just curious... if people are using an alternate browser they are fine right? So if running Windows XP SP3 fully patched and Firefox 29, as long as they dont use IE as their browser they should be fine right? Or can a script on a web site with flash on say Firefox explicitly call IE? To me for IE to be called directly through use of say Firefox 29, someone would have to download and run a script manually that targets IE through alternate browsers.  :-\

evilfantasy

    Topic Starter
  • Malware Removal Specialist


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #12 on: May 01, 2014, 02:03:41 PM »
I would imagine that any browser using the IE technology (Trident) could be vulnerable. I'm not sure though.

Flash was patched and now IE has been fully patched so, to me, this is a good example to why people should use the more popular browsers. They may be targeted for exploit more often but they are also more secure.

PCdoc



    Hopeful

    Thanked: 32
    • Yes
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 7
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #13 on: May 01, 2014, 11:53:54 PM »
And then they released a fix for XP users. Read Article
....

DaveLembke



    Sage
  • Thanked: 662
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 10
Re: Vulnerability Found in Every Single Version of Internet Explorer
« Reply #14 on: May 02, 2014, 07:37:05 PM »
Quote
Microsoft is helping the estimated hundreds of millions of customers still running Windows XP, which it stopped supporting earlier this month


I guess this was written at the end of April and then released on 5/2 ... or the writer didnt realize that its May already. Either way cool to see that Microsoft stepped up to the plate with a fix for this. I will have to patch my one XP system when I get home from work even though I don't use IE but use Firefox instead. As evilfantasy pointed out earlier due to Trident ( IE Technology ) that carried over to other browsers its best to be safe than sorry.