UPDATED 22:22 EST / DECEMBER 19 2018

SECURITY

Microsoft issues urgent security update for Internet Explorer

Microsoft Corp. today issued a rare standalone security update for Internet Explorer after the discovery of an actively exploited vulnerability.

Discovered by Google LLC’s Threat Analysis Group, it’s described as a vulnerability in the way in which the Internet Explorer scripting engine handles objects in memory.

“The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user,” Microsoft explained in a so-called “out-of-band” security advisory. “An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.”

The company added that if the current user is logged on with administrative user rights, “an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”

The vulnerability can be triggered in a variety of ways, including via a specially crafted web page that a user visits according to the Cisco Talos Intelligence Group.

Satnam Narang, senior research engineer at Tenable Inc., told SiliconANGLE that the vulnerability is being actively exploited. “While details are not currently available, in most cases, attackers exploit similar vulnerabilities by sending convincing emails to their intended targets with a link to a specially crafted website containing the exploit code,” Narang explained.

The vulnerability affects Internet Explorer 11 from Windows 7 to Windows 10 as well as Windows Server 2012, 2016 and 2019. Internet Explorer 9 is affected on Windows Server 2008, while Internet Explorer 10 is affected on Windows Server 2012. A patch has been pushed out to users of Windows 7, 8.1 and 10 as well as Windows Server 2008, 2012, 2016 and 2019.

“As the flaw is being actively exploited in the wild, users are urged to update their systems as soon as possible to reduce the risk of compromise,” Narang added.

Image: Maxpixel

Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.