HomeSecuritySecurity Update: Microsoft fixes zero-day vulnerabilities in IE and Windows Defender

Security Update: Microsoft fixes zero-day vulnerabilities in IE and Windows Defender

Security Update: Microsoft has released an urgent security update to fix two security vulnerabilities affecting Internet Explorer and Windows Defender.

Of these two, the first is a remote code execution (RCE) flaw, registered as CVE-2019-1367. This zero-day vulnerability affects Internet Explorer versions 9, 10, and 11 (which are still widely used) and exploits the way “Microsoft’s scripting engine handles objects in IE’s memory.”

 Microsoft

According to Microsoft, hackers could exploit this vulnerability by luring potential targets (using spam emails, malicious ads, search engine ads, IM spam, and more) to visit a website infected through the Internet Explorer vulnerability.

The flaw could corrupt system memory and allow attackers to execute arbitrary code in the context of the legitimate user. Exploiting the flaw allows an attacker to achieve the same user rights as the legitimate user.

Therefore, if a user logs in as a system administrator, a successful attack could allow hackers to gain complete control of the affected system. Once they gain administrator privileges, the attacker would be able to edit or delete data, install new programs, and create new accounts.

Security Update

This RCE vulnerability has already been exploited, according to Microsoft.

The patch to resolve this vulnerability can only be installed manually after downloading the patch from the Microsoft Update Catalog.

The second vulnerability that has been fixed is a Denial of Service (DoS) bug that affects the Windows Defender tool.

It is listed as CVE-2019-1255 and was found by Wenxu Wu and Charalampos Billinis of Tencent Security Xuanwu Lab and F-Secure Countercept, respectively.

Microsoft said an attacker could exploit this flaw to prevent legitimate users from running legitimate system binaries. However, they would first need system execution in order to exploit the vulnerability.

So far, there are no reports of whether the bug has been exploited by hackers.

Users do not need to download the patch for this bug, as Microsoft's Malware Protection Engine will automatically install the new security update

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS