A few days ago we posted about a new Internet Explorer Zero Day that had surfaced. The name of the vulnerability according to Microsoft is CVE-2014-1776.
Cybercriminals, as Microsoft reports, began carrying out “limited targeted attacks,” meaning that scammers were not using malicious web links indiscriminately, but were choosing to focus on a small group of victims.
Of course, many people preferred to use temporary measuresto protect themselves while they waited for the official fix from Microsoft.
The attacks targeted IE 9, 10 and 11 and used a Flash file and a Microsoft IE extension called Vgx.dll which is used for vector graphics rendering.
But we have good news.
Microsoft has released a security bulletin announcing the immediate availability of the code that closes this vulnerability. This means you won't have to wait until the next Patch Tuesday for an updated version. HM
The company states:
All versions of IE on all versions of Windows contain a security flaw that could allow cybercriminals to inject malicious software onto your computer with little or no warning.
Microsoft has released a security update that closes this flaw so that it can no longer be used to attack your computer.
We recommend that you download the update as soon as possible, if you haven't already.
Go to Control Panel | Windows Update if you're not sure where to start.
Of course, here comes the surprise as it seems that the company even released updates for Windows XP users.
Affected Software
| Operating System | Component | Maximum Security Impact | Aggregate Severity Rating | Updates Replaced |
|---|---|---|---|---|
| Internet Explorer 6 | ||||
| Windows XP Service Pack 3 | Internet Explorer 6 (2964358) | Remote Code Execution | Critical | None |
| Windows XP Professional x64 Edition Service Pack 2 | Internet Explorer 6 (2964358) | Remote Code Execution | Critical | None |
| Windows Server 2003 Service Pack 2 | Internet Explorer 6 (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2003 x64 Edition Service Pack 2 | Internet Explorer 6 (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2003 with SP2 for Itanium-based Systems | Internet Explorer 6 (2964358) | Remote Code Execution | Moderate | None |
| Internet Explorer 7 | ||||
| Windows XP Service Pack 3 | Internet Explorer 7 (2964358) | Remote Code Execution | Critical | None |
| Windows XP Professional x64 Edition Service Pack 2 | Internet Explorer 7 (2964358) | Remote Code Execution | Critical | None |
| Windows Server 2003 Service Pack 2 | Internet Explorer 7 (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2003 x64 Edition Service Pack 2 | Internet Explorer 7 (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2003 with SP2 for Itanium-based Systems | Internet Explorer 7 (2964358) | Remote Code Execution | Moderate | None |
| Windows Vista Service Pack 2 | Internet Explorer 7 (2964358) | Remote Code Execution | Critical | None |
| Windows Vista x64 Edition Service Pack 2 | Internet Explorer 7 (2964358) | Remote Code Execution | Critical | None |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | Internet Explorer 7 (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2008 for x64-based Systems Service Pack 2 | Internet Explorer 7 (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2008 for Itanium-based Systems Service Pack 2 | Internet Explorer 7 (2964358) | Remote Code Execution | Moderate | None |
| Internet Explorer 8 | ||||
| Windows XP Service Pack 3 | Internet Explorer 8 (2964358) | Remote Code Execution | Critical | None |
| Windows XP Professional x64 Edition Service Pack 2 | Internet Explorer 8 (2964358) | Remote Code Execution | Critical | None |
| Windows Server 2003 Service Pack 2 | Internet Explorer 8 (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2003 x64 Edition Service Pack 2 | Internet Explorer 8 (2964358) | Remote Code Execution | Moderate | None |
| Windows Vista Service Pack 2 | Internet Explorer 8 (2964358) | Remote Code Execution | Critical | None |
| Windows Vista x64 Edition Service Pack 2 | Internet Explorer 8 (2964358) | Remote Code Execution | Critical | None |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | Internet Explorer 8 (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2008 for x64-based Systems Service Pack 2 | Internet Explorer 8 (2964358) | Remote Code Execution | Moderate | None |
| Windows 7 for 32-bit Systems Service Pack 1 | Internet Explorer 8 (2964358) | Remote Code Execution | Critical | None |
| Windows 7 for x64-based Systems Service Pack 1 | Internet Explorer 8 (2964358) | Remote Code Execution | Critical | None |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Internet Explorer 8 (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 | Internet Explorer 8 (2964358) | Remote Code Execution | Moderate | None |
| Internet Explorer 9 | ||||
| Windows Vista Service Pack 2 | Internet Explorer 9 (2964358) | Remote Code Execution | Critical | None |
| Windows Vista x64 Edition Service Pack 2 | Internet Explorer 9 (2964358) | Remote Code Execution | Critical | None |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | Internet Explorer 9 (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2008 for x64-based Systems Service Pack 2 | Internet Explorer 9 (2964358) | Remote Code Execution | Moderate | None |
| Windows 7 for 32-bit Systems Service Pack 1 | Internet Explorer 9 (2964358) | Remote Code Execution | Critical | None |
| Windows 7 for x64-based Systems Service Pack 1 | Internet Explorer 9 (2964358) | Remote Code Execution | Critical | None |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Internet Explorer 9 (2964358) | Remote Code Execution | Moderate | None |
| Internet Explorer 10 | ||||
| Windows 7 for 32-bit Systems Service Pack 1 | Internet Explorer 10 (2964358) | Remote Code Execution | Critical | None |
| Windows 7 for x64-based Systems Service Pack 1 | Internet Explorer 10 (2964358) | Remote Code Execution | Critical | None |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Internet Explorer 10 (2964358) | Remote Code Execution | Moderate | None |
| Windows 8 for 32-bit Systems | Internet Explorer 10 (2964358) | Remote Code Execution | Critical | None |
| Windows 8 for x64-based Systems | Internet Explorer 10 (2964358) | Remote Code Execution | Critical | None |
| Windows Server 2012 | Internet Explorer 10 (2964358) | Remote Code Execution | Moderate | None |
| Windows RT | Internet Explorer 10[1] (2964358) | Remote Code Execution | Critical | None |
| Internet Explorer 11 | ||||
| Windows 7 for 32-bit Systems Service Pack 1 | Internet Explorer 11 [2] (2964358) | Remote Code Execution | Critical | None |
| Windows 7 for 32-bit Systems Service Pack 1 | Internet Explorer 11 (2964444) | Remote Code Execution | Critical | None |
| Windows 7 for x64-based Systems Service Pack 1 | Internet Explorer 11 [2] (2964358) | Remote Code Execution | Critical | None |
| Windows 7 for x64-based Systems Service Pack 1 | Internet Explorer 11 (2964444) | Remote Code Execution | Critical | None |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Internet Explorer 11 [2] (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | Internet Explorer 11 (2964444) | Remote Code Execution | Moderate | None |
| Windows 8.1 for 32-bit Systems | Internet Explorer 11 [3] (2964358) | Remote Code Execution | Critical | None |
| Windows 8.1 for 32-bit Systems | Internet Explorer 11 (2964444) | Remote Code Execution | Critical | None |
| Windows 8.1 for x64-based Systems | Internet Explorer 11 [3] (2964358) | Remote Code Execution | Critical | None |
| Windows 8.1 for x64-based Systems | Internet Explorer 11 (2964444) | Remote Code Execution | Critical | None |
| Windows Server 2012 R2 | Internet Explorer 11 [3] (2964358) | Remote Code Execution | Moderate | None |
| Windows Server 2012 R2 | Internet Explorer 11 (2964444) | Remote Code Execution | Moderate | None |
| Windows 8.1 | Internet Explorer 11[1][3] (2964358) | Remote Code Execution | Critical | None |
| Windows 8.1 | Internet Explorer 11[1] (2964444) | Remote Code Execution | Critical | None |
[1]This update is available via Windows Update.
[2]This update is for systems that have the 2961851 update installed. See the Update FAQ for more information.
[3]This update is for systems that have the 2919355 update installed. See the Update FAQ for more information.
Non-Applicable Software
| Operating System | Component |
|---|---|
| Server Core installation | |
| Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | Not applicable |
| Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | Not applicable |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | Not applicable |
| Windows Server 2012 (Server Core installation) | Not applicable |
| Windows Server 2012 R2 (Server Core installation) | Not applicable |

