News Vulnerability Management
Microsoft Issues Patch For Critical IE Vulnerability
Internet Explorer flaw could enable attackers to take over a user's computer
Microsoft has issued a patch to repair a critical vulnerability in Internet Explorer that could allow attackers to take control of an end user's computer.
In its monthly security patch update, the software giant provides a solution for the IE bug, which was disclosed in early January.
More Security Insights
White Papers
- A Smarter Approach: Inside IBM Business Analytics Solutions for Mid-Size Businesses
- Collective intelligence: Capitalizing on the crowd
Reports
- Informed CIO: SDN and Server Virtualization on a Collision Course
- Strategy: Building and Maintaining Database Access Control Permissions
Webcasts
- Mobile DevOps: Achieving continuous delivery with multiple front ends and complex backends in Banking, Financial Services, and Insurance
- How Cloud Facilitates an Agile Contact Center
The flaw enabled attackers to create new exploits that cheat two widely respected Microsoft security features and wage targeted attacks on end user computers.
The vulnerability could allow remote code execution if a user views a specially crafted Web page -- sometimes called a "watering hole" -- using Internet Explorer, Microsoft said. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user.
The flaw affects users of Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8, Microsoft stated. Internet Explorer 9 and Internet Explorer 10 are not affected.
The security update fixes the vulnerability by modifying the way that Internet Explorer handles objects in memory, Microsoft said.
Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.
Related Reading
Dark Reading Discussions
Start the Discussion
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |











