Trending News

Even the U.S. and UK Governments say stop using Internet Explorer

Even the US and UK Governments say stop using Internet Explorer

Alexandra Burlacu

Microsoft has issued a warning regarding a recently-discovered zero-day flaw in Internet Explorer, and even the U.S. and UK governments advise consumers to stop using the browser.

This severe vulnerability is the first one to be discovered after Microsoft put its old Windows XP to bed, and affects all versions of the software starting with Internet Explorer 6. This means that all subsequent versions - IE7, IE8, IE9, IE10, and IE11 - are affected as well, not just IE 6. If exploited, the vulnerability could allow for the remote execution of code, posing serious risks.

"The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated," Microsoft explains. "The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer."

In light of these findings, the United States Computer Emergency Readiness Team - US-CERT and its UK counterpart - UK-CERT - have issued warnings themselves to advise users at risk.

"US-CERT is aware of active exploitation of a use-after-free vulnerability in Microsoft Internet Explorer. This vulnerability affects IE versions 6 through 11 and could allow unauthorized remote code execution," reads a warning. "US-CERT recommends that users and administrators review Microsoft Security Advisory 2963983 for mitigation actions and workarounds. Those who cannot follow Microsoft's recommendations, such as Windows XP users, may consider employing an alternate browser."

According to Microsoft, however, the vulnerability is not that easy to exploit. In order to exploit it via the web, an attacker would need to set up a specially designed website containing code, and would also have to convince people to access the website. Even so, the company still strongly recommends that all users run an enabled firewall, apply all available software updates, and install reliable and efficient anti-malware software to protect their machines.

While it is highly advisable to use an alternate browser, those who still want to use Internet Explorer can at least reduce the risk by taking some precautionary measures. For instance, Internet Explorer in Windows Server versions 2003, 2008, 2008 R2, 2012, and 2012 R2, runs in a restricted mode by default. This Enhanced Security Configuration can significantly reduce the risk of exposure to the flaw. Similarly, Microsoft Outlook, Outlook Express, and Windows Mail also minimize the risk by opening HTML email messages in the Restricted sites zone.

As far as actually solving the issue goes, currently there is no fix available. Microsoft said that a solution may arrive either via its monthly security update release, or through an out-of-cycle security update. The company has yet to provide a date for when a patch will become available to solve the issue.

As expected, Windows XP users will not receive any patch to fix this vulnerability, as Microsoft has ended all support for the old OS earlier this month. For other versions of Windows, use an alternate browser until Microsoft issues a patch. 

© Copyright 2020 Mobile & Apps, All rights reserved. Do not reproduce without permission.

more stories from Trending News

  • Trending News

    The Slip and Fall Law

    The onus lies on you to prove to the insurance company that the property's hazardous situations caused your fall and injuries.

  • How To

    Tax Tips for Small Businesses

    Tax is an uncomfortable subject for some people. It's complicated but compulsory. Small business owners may feel overwhelmed by the regulations

  • Trending News

    4 SEO Problems That a New Website Won't Fix

    Are you considering blowing up your website and building it from scratch? Are you unhappy with how your current site is performing or ranking?

  • Culture

    The Best Projects for Your Raspberry Pi

    If you haven't heard of the Raspberry Pi, this device represents one of the best and most handy innovations of the previous decade. If you haven't heard of the Raspberry Pi, this device represents one of the best and most handy innovations of the previous decade.

  • Trending News

    Five Tips for Building a Website When You Don't Have a Lot of Time

    There was once a time when websites were just for businesses and bloggers. That's not the case anymore. Today, everyone should have a website. Even if you aren't starting a small business and don't want to spend every spare minute writing articles for your blog, having a website is like having a digital business card. It's a great way to showcase your professional portfolio for anyone and everyone who might be interested in hiring you.

  • Trending News

    5 Things You Should Know About Investment Intelligence

    Investors know that investing money is always a big decision. With that being said, on the one hand, there are risks involved, and, on the other, there are also opportunities for great returns. This causes investors to be very strategic about their decision-making process.

  • Trending News

    Tips for Using Google Ads in 2020

    Google Ads is a tremendously powerful advertising platform. You can target specific types of people, searching for specific things at specific times of the day, in specific locations!

  • Trending News

    How to Use Digital Strategy to Promote Your Online Business

    Your business's digital strategy must be revisited regularly and adjusted to your company’s needs. In the ever-changing world of online business, you need to make sure that your venture stays relevant and that you're always one step ahead of your competitors.

    To have the biggest impact, build a strong website and concentrate on SEO, which you can boost through a blog. Focus on email marketing campaigns, press releases, and competitions to raise awareness. If you aren’t sure where to start, outsource to a consultant.

Back
Real Time Analytics