Microsoft has just released a patch accompanied by a security advisory and informs about a new critical vulnerability in the company's Internet Explorer web browser.
The vulnerability, which is already known on the internet, according to the company affects Internet Explorer 7-11 on client and server operating systems.
The new Microsoft Edge browser, the default web browser on Windows 10, is not affected by this vulnerability.
The vulnerability has been classified as critical for all client operating systems and as moderate for all server operating systems of the company.
Microsoft provided patches for all operating systems that have a problem and you can download them immediately via Windows Update as well as the company's download center.
The update is listed as “Cumulative Update for Windows 10 (KB3081444)” for Windows 10, and as KB3087985 for all previous versions of Windows. Update KB3078071 is required for this update on Windows 8.1 and 7, as well as Windows Server 2008 R2 and 2012 R2.
Attackers can exploit the vulnerability in various ways, for example by creating websites that exploit the flaw, HTML email messages or web advertisements. If any of the above are loaded in a version of Internet Explorer.
Attackers can obtain the same privileges as the current system user. If the logged-in user has administrator rights, then the malicious users gain administrator privileges.
You can read more details from the link below:
Microsoft Security Bulletin MS15-093 – Critical
