Jump to content

Critical exploits plague IE11 but MS is too busy with W10 to patch them

Bloodyvalley

Four zero-day vulnerabilities have been discovered in Microsoft’s Internet Explorer as the company makes plans for launching its upcoming Windows 10 next week, on July 29.

internet-explorer-security-hole.jpg

Critical Internet Explorer vulnerabilities:

While you may like it or not, Internet Explorer is still one of the most used browsers in world as it comes pre-loaded on PCs, notebooks, and Windows Phones. Recent years have seen a strong shift to better and more safer browsers, but Internet Explorer still remains the default browser for many. Such a strong user base makes the platform traditionally a favorite place for hackers. The Hewlett-Packard’s Zero-Day Initiative (ZDI) has disclosed four new vulnerabilities in the browser that could be potentially exploited to remotely execute malicious code on the target machine. This remote execution of code is possible on your machine even if your browser is fully updated.

These four bugs have been reported to be affecting IE11 on Windows Phones. The tipping point?

HP reported these critical zero-day Internet Explorer bugs to Microsoft some six months back, however, considering how Redmond has stayed busy with the development of Windows 10, it couldn’t manage to fix the issue. Microsoft was notified of the first zero-day Internet Explorer bug on November 12, 2014 which was then extended to May 12, 2015 and then again to July 19. However, as no patch came to fix the issue, ZDI went public on July 22. Microsoft reportedly requested HP to give another extension of 6 months grace period before HP makes these vulnerabilities public but HP refused the request. Now published, we expect to see Microsoft responding to this more responsibly and possibly sending some patch our way too.

We’re aware of the reports regarding Internet Explorer for Windows Phone. A number of factors would need to come into play, and no attacks have been reported. We continue to monitor the situation and will take appropriate steps to protect our customers.
– Microsoft’s statement

Microsoft is replacing the aging Internet Explorer with Microsoft Edge browser once Windows 10 is launched. However, Internet Explorer will keep serving the enterprise customers and, of course, the machines not updated to Windows 10.

 

 

but who even uses IE

 

source

Link to comment
Share on other sites

Link to post
Share on other sites

but who even uses IE

businesses

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
Share on other sites

Link to post
Share on other sites

businesses

 

T-Mobile still uses XP :)

 

 

 

tim2heck ( ͡° ͜ʖ ͡°)

Link to comment
Share on other sites

Link to post
Share on other sites

 

 

but who even uses IE

 

source

IE has actually been great since v11. I'm pretty sure that most of the IE haters have not even given it a chance since v8 and 9, which WERE awful.

Nowadays, I find IE both more stable and just all around less stupid than dealing with Chrome and its memory hog-ness.

When in doubt, re-format.

Link to comment
Share on other sites

Link to post
Share on other sites

More companies than you'd expect use IE. 

Link to comment
Share on other sites

Link to post
Share on other sites

but who even uses IE

About 51% of the market.

 

https://www.netmarketshare.com/browser-market-share.aspx?qprid=2&qpcustomd=0

Main Rig: CPU: AMD Ryzen 7 5800X | RAM: 32GB (2x16GB) KLEVV CRAS XR RGB DDR4-3600 | Motherboard: Gigabyte B550I AORUS PRO AX | Storage: 512GB SKHynix PC401, 1TB Samsung 970 EVO Plus, 2x Micron 1100 256GB SATA SSDs | GPU: EVGA RTX 3080 FTW3 Ultra 10GB | Cooling: ThermalTake Floe 280mm w/ be quiet! Pure Wings 3 | Case: Sliger SM580 (Black) | PSU: Lian Li SP 850W

 

Server: CPU: AMD Ryzen 3 3100 | RAM: 32GB (2x16GB) Crucial DDR4 Pro | Motherboard: ASUS PRIME B550-PLUS AC-HES | Storage: 128GB Samsung PM961, 4TB Seagate IronWolf | GPU: AMD FirePro WX 3100 | Cooling: EK-AIO Elite 360 D-RGB | Case: Corsair 5000D Airflow (White) | PSU: Seasonic Focus GM-850

 

Miscellaneous: Dell Optiplex 7060 Micro (i5-8500T/16GB/512GB), Lenovo ThinkCentre M715q Tiny (R5 2400GE/16GB/256GB), Dell Optiplex 7040 SFF (i5-6400/8GB/128GB)

Link to comment
Share on other sites

Link to post
Share on other sites

I don't like Chrome and I don't like Firefox

CPU: AMD 7800X3D Motherboard: NZXT B650E RAM: 32GB 5600 30-CL Corsair Vengeance DDR5 GPU: MSI Gaming X Trio RTX 2070 PSU: Corsair RM850i Monitor: Samsung 27" 4K thing Cooling:Noctua Chromax Black NH-D15: Case: NZXT H510 Black

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

but who even uses IE

 

source

I do at work, because the vast majority of the customers (businesses) that use our web interface use internet explorer, and it has to work.

Intel i7 5820K (4.5 GHz) | MSI X99A MPower | 32 GB Kingston HyperX Fury 2666MHz | Asus RoG STRIX GTX 1080ti OC | Samsung 951 m.2 nVME 512GB | Crucial MX200 1000GB | Western Digital Caviar Black 2000GB | Noctua NH-D15 | Fractal Define R5 | Seasonic 860 Platinum | Logitech G910 | Sennheiser 599 | Blue Yeti | Logitech G502

 

Nikon D500 | Nikon 300mm f/4 PF  | Nikon 200-500 f/5.6 | Nikon 50mm f/1.8 | Tamron 70-210 f/4 VCII | Sigma 10-20 f/3.5 | Nikon 17-55 f/2.8 | Tamron 90mm F2.8 SP Di VC USD Macro | Neewer 750II

Link to comment
Share on other sites

Link to post
Share on other sites

Maybe I can finally use this to convince my mom to not use IE

Link to comment
Share on other sites

Link to post
Share on other sites

There's a simple solution.

 

Don't use Internet Explorer.

it's not quite that simple. On a consumer level that works fine -- most of the time -- but on an enterprise level you run into some serious issues with trying to transfer everyone to a different browser. Including a learning curve in some cases, but far more importantly, not everything is compatible with everything else -- IE, on the other hand, tends to be compatible with almost everything.

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
Share on other sites

Link to post
Share on other sites

To answer the question who uses IE, it is a requirement for some of my work.

 

We use Siebel CRM 8.0 software and we use it as a web application and it requires Internet Explorer. For the longest time it wouldn't work with anything higher than IE8. And on top of that it only works with the 32-bit version of IE.

 

Literally just last week we were finally allowed to upgrade to IE11. They had to make sure nothing would break with any of the applications we use.

 

It's insane how exact software and configurations need to be when working with software like Siebel, which is fucking massive. Everything is so specific. Even if one little setting in your browser isn't right it can cause the whole thing to not work. We have a script that we run on our computer that automatically sets all of IE's settings to what they need to be.

CPU: i7 4790K  RAM: 32 GB 2400 MHz  Motherboard: Asus Z-97 Pro  GPU: GTX 770  SSD: 256 GB Samsung 850 Pro  OS: Windows 8.1 64-bit

Link to comment
Share on other sites

Link to post
Share on other sites

Does anyone even BOTHER to read the source? This is for Windows Phone IE 11 only.

For Sale: Meraki Bundle

 

iPhone Xr 128 GB Product Red - HP Spectre x360 13" (i5 - 8 GB RAM - 256 GB SSD) - HP ZBook 15v G5 15" (i7-8850H - 16 GB RAM - 512 GB SSD - NVIDIA Quadro P600)

 

Link to comment
Share on other sites

Link to post
Share on other sites

Does anyone even BOTHER to read the source? This is for Windows Phone IE 11 only.

Oh GREAT, that's exactly what I use.

 

Not for anything other than reading the news, but still.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

Does anyone even BOTHER to read the source? This is for Windows Phone IE 11 only.

 

"While you may like it or not, Internet Explorer is still one of the most used browsers in world as it comes pre-loaded on PCs, notebooks, and Windows Phones. Recent years have seen a strong shift to better and more safer browsers, but Internet Explorer still remains the default browser for many. Such a strong user base makes the platform traditionally a favorite place for hackers."

 

While the source does say Windows Phone, it goes out of its way to imply otherwise.

Link to comment
Share on other sites

Link to post
Share on other sites

"While you may like it or not, Internet Explorer is still one of the most used browsers in world as it comes pre-loaded on PCs, notebooks, and Windows Phones. Recent years have seen a strong shift to better and more safer browsers, but Internet Explorer still remains the default browser for many. Such a strong user base makes the platform traditionally a favorite place for hackers."

 

While the source does say Windows Phone, it goes out of its way to imply otherwise.

 

That's shoddy journalism. I can't say for certain it's 100% only Windows Phone, but the article specifically says:

 

These four bugs have been reported to be affecting IE11 on Windows Phones.

 

So you're right, the article does heavily imply otherwise, but that's just straight up shitty journalism. The article is unclear and sends mixed messages and contradictory information.

For Sale: Meraki Bundle

 

iPhone Xr 128 GB Product Red - HP Spectre x360 13" (i5 - 8 GB RAM - 256 GB SSD) - HP ZBook 15v G5 15" (i7-8850H - 16 GB RAM - 512 GB SSD - NVIDIA Quadro P600)

 

Link to comment
Share on other sites

Link to post
Share on other sites

Does anyone even BOTHER to read the source? This is for Windows Phone IE 11 only.

Well shit. I guess I'm at risk.

Every topic I post in dies.

Link to comment
Share on other sites

Link to post
Share on other sites

Oh GREAT, that's exactly what I use.

 

Not for anything other than reading the news, but still.

 

 

Well shit. I guess I'm at risk.

 

Me too, but I wouldn't stress too much. There have been no reported attacks, and now that this is out in the open, I expect Microsoft to quickly patch it.

 

If you want to help, then try Tweeting at the Microsoft/Windows Phone twitter handle, asking them to patch the exploit (Make sure to link the source article).

For Sale: Meraki Bundle

 

iPhone Xr 128 GB Product Red - HP Spectre x360 13" (i5 - 8 GB RAM - 256 GB SSD) - HP ZBook 15v G5 15" (i7-8850H - 16 GB RAM - 512 GB SSD - NVIDIA Quadro P600)

 

Link to comment
Share on other sites

Link to post
Share on other sites

Does anyone even BOTHER to read the source? This is for Windows Phone IE 11 only.

article is clickbait at its finest, looking at the headline and that they mentioned WP once on a single line in the middle, its just that

 

while i agree MS dropped the ball in fixing this, they probably said fuck it, due to being busy making edge a proper browser and that it will replace IE with the win 10 update

this is one of the greatest thing that has happened to me recently, and it happened on this forum, those involved have my eternal gratitude http://linustechtips.com/main/topic/198850-update-alex-got-his-moto-g2-lets-get-a-moto-g-for-alexgoeshigh-unofficial/ :')

i use to have the second best link in the world here, but it died ;_; its a 404 now but it will always be here

 

Link to comment
Share on other sites

Link to post
Share on other sites

article is clickbait at its finest, looking at the headline and that they mentioned WP once on a single line in the middle, its just that

 

while i agree MS dropped the ball in fixing this, they probably said fuck it, due to being busy making edge a proper browser and that it will replace IE with the win 10 update

Not to mention that Windows Mobile 10 launches soon, and is a free upgrade to 90% of the current Windows Phone 8.1 devices (Since most of them are Nokia, and pretty much almost all the Lumia's will get the free upgrade).

 

I do hope they fix it soon though.

For Sale: Meraki Bundle

 

iPhone Xr 128 GB Product Red - HP Spectre x360 13" (i5 - 8 GB RAM - 256 GB SSD) - HP ZBook 15v G5 15" (i7-8850H - 16 GB RAM - 512 GB SSD - NVIDIA Quadro P600)

 

Link to comment
Share on other sites

Link to post
Share on other sites

IE has actually been great since v11. I'm pretty sure that most of the IE haters have not even given it a chance since v8 and 9, which WERE awful.

Nowadays, I find IE both more stable and just all around less stupid than dealing with Chrome and its memory hog-ness.

IE has been "tolerable" since IE 11. Calling it great is an exaggeration since it's still quite a lot slower than the competitors, has much worse support for web standards, barely any extensions, awful image scaling and a GUI designed by an idiot.

 

The only good thing I have to say about IE 11 is that Inori Aizawa is cute, but that doesn't have anything to do with the actual browser.

 

 

 

The Ars Technica article is a lot better than the WCCFtech article (big surprise, right?).

It doesn't seem like Microsoft just went "lol who cares about IE 11. We're busy working on Windows 10!". It was only like a week ago they patched another security hole in IE.

 

What I think happened here is the reason why making security issues public if the company affected don't meet deadlines is important. Microsoft probably knew that nobody had taken advantage of the exploit yet so they just went "Fuck it. We got more important things to do" and then asked for a 4 month deadline extension which was granted. They they worked on other stuff and kind of forgot about it and asked for another extension on the deadline. HP were very generous to give them 8 months to fix it before going public, and Microsoft wanted even more time.

 

 

It's not clear to me if this is a phone only issue or not. Microsoft's own statement only mentions Windows Phone, but from what I can tell this affects the desktop too. This vulnerabilities details says "This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer, including on Windows Phone.". The other 3 vulnerabilities don't mention phone whatsoever.

Link to comment
Share on other sites

Link to post
Share on other sites

Cool.

Quote

Ignis (Primary rig)
CPU
 i7-4770K                               Displays Dell U2312HM + 2x Asus VH236H
MB ASRock Z87M Extreme4      Keyboard Rosewill K85 RGB BR
RAM G.Skill Ripjaws X 16GB      Mouse Razer DeathAdder
GPU XFX RX 5700XT                    Headset V-Moda Crossfade LP2
PSU Lepa G1600
Case Corsair 350D
Cooling Corsair H90             
Storage PNY CS900 120GB (OS) + WD Blue 1TB

Quote

Server 01Alpha                                       Server 01Beta                            Chaos Box (Loaner Rig)                Router (pfSense)
CPU
 Xeon X5650                                      CPU 2x Xeon E5520                    CPU Xeon E3-1240V2                     CPU Xeon E3-1246V3
MB Asus P6T WS Pro                               MB EVGA SR-2                             MB ASRock H61MV-ITX                 MB ASRock H81 Pro BTC
RAM Kingston unbuffered ECC 24GB  RAM G.Skill Ripjaws 16GB         RAM Random Ebay RAM 12GB    RAM G.Skill Ripjaws 8GB
GPU XFX R5 220                                       GPU EVGA GTX 580 SC               GPU Gigabyte R9 295x2                GPU integrated
PSU Corsair CX430M                               PSU Corsair AX1200                   PSU Corsair GS700                         PSU Antec EA-380D
Case Norco RPC-450B 4U                      Case Rosewill  RSV-L4000C        Case Modified Bitfenix Prodigy   Case Norco RPC-250 2U
Cooling Noctua NH-U9S                        Cooling 2x CM Hyper 212 Evo  Cooling EVGA CLC 120mm           Cooling stock
Storage PNY CS900 120GB (OS)           Storage null                                 Storage PNY CS900 120GB (OS)  Storage Fujitsu 150GB HDD
               8x WD Red 1TB in Raid 6                                                                                WD Black 1TB    
               WD Green 2TB

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×