IE Vulnerability
By Chris Eburne · Module IT
Microsoft has been trying to get people off Internet Explorer for a while, pushing Microsoft Edge as the default browser on Windows 10. But IE still persists, stubbornly showing up in lists of the most popular web browsers.
A Critical Zero-Day
A critical zero-day vulnerability was found that makes Internet Explorer vulnerable to hijacking. According to Microsoft's own advisory, the vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative rights, an attacker who successfully exploited the vulnerability could take control of an affected system.
Microsoft confirmed this vulnerability had already been exploited in the wild, though a patch was made available.
How the Attack Works
In a web-based attack scenario, an attacker could host a specially crafted website designed to exploit the vulnerability through Internet Explorer, then convince a user to view it, for example by sending a phishing email.
What You Should Do
- Move all users to Microsoft Edge or another modern browser immediately
- Apply all available Windows and IE security patches
- Consider blocking IE via Group Policy if users still rely on it
Get in touch with Module IT if you need help securing your browser environment or rolling out Edge across your organisation.
Get expert IT insights in your inbox
Cyber security, AI readiness, VoIP migration — no fluff, just actionable intelligence for UK businesses.