Microsoft Issues Emergency Fix for IE Zero Day
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-8653 | Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine CVE-2018-8653 is a memory corruption vulnerability (out-of-bounds write, CWE-787) in how the Microsoft Internet Explorer scripting engine handles objects in memory. An attacker typically triggers it by getting a user to view specially crafted web content in Internet Explorer, causing memory corruption during script object handling. Successful exploitation yields remote code execution with the privileges of the logged-on user, allowing arbitrary code to run on the victim machine. Any system running Microsoft Internet Explorer is affected; because IE ships with Windows and remains in use for legacy enterprise web applications, the plausibly affected population is large, on the order of hundreds of millions of users and devices. The flaw is confirmed exploited in the wild via CISA's KEV catalog (added 2021-11-03, ransomware use unknown), carries a high EPSS score of 29.8% (98th percentile) for exploitation in the next 30 days, and has no known public PoC. Do: Apply Microsoft's security updates for Internet Explorer on all Windows systems per vendor instructions, which is CISA's required action for this KEV-listed flaw. Confirm IE cumulative updates are current through Windows Update/WSUS, prioritize endpoints and servers running legacy intranet web applications, and restrict or retire legacy IE-based browsing where feasible while monitoring for follow-on exploitation. | 7.5 | 30% | KEV |
| massWell over 1M users |
Full article231 words · extracted from krebsonsecurity.com · click to collapse
Microsoft today released an emergency software patch to plug a critical security hole in its Internet Explorer (IE) Web browser that attackers are already using to break into Windows computers.
The software giant said it learned about the weakness (CVE-2018-8653) after receiving a report from Google about a new vulnerability being used in targeted attacks.
Satnam Narang, senior research engineer at Tenable, said the vulnerability affects the following installations of IE: Internet Explorer 11 from Windows 7 to Windows 10 as well as Windows Server 2012, 2016 and 2019; IE 9 on Windows Server 2008; and IE 10 on Windows Server 2012.
“As the flaw is being actively exploited in the wild, users are urged to update their systems as soon as possible to reduce the risk of compromise,” Narang said.
According to a somewhat sparse advisory about the patch, malware or attackers could use the flaw to break into Windows computers simply by getting a user to visit a hacked or booby-trapped Web site. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Microsoft says users who have Windows Update enabled and have applied the latest security updates are protected automatically. Windows 10 users can manually check for updates this way; instructions on how to do this for earlier versions of Windows are here.
Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2018/12/microsoft-issues-emergency-fix-for-ie-zero-day/