HomeSecurityMicrosoft fixes zero-day vulnerability in Internet Explorer

Microsoft fixes zero-day vulnerability in Internet Explorer

Microsoft fixes zero-day vulnerability in Internet Explorer

Microsoft released its Patch Tuesday February 2020 yesterday , which fixes a total of 99 vulnerabilities . However, the most significant issue being fixed is a zero-day vulnerability that allows remote code execution and affects multiple versions of Internet Explorer .

The vulnerability was disclosed by Microsoft itself in mid-January 2020. The company had released a security advisory to warn users about a zero-day vulnerability in Internet Explorer ( CVE-2020-0674 ), which was already being exploited by hackers .

The zero-day vulnerability was discovered and reported by Clément Lecigne from Google 's threat analysis team and Ella Yu from Qihoo 360. According to the experts: the vulnerability "could corrupt memory in such a way that an attacker could execute code when the user is using the vulnerable system ."

If the user is logged in with administrator privileges on a vulnerable device, attackers can gain full control of the system and therefore can install programs and manipulate data.

Microsoft fixes zero-day vulnerability in Internet Explorer
FILE PHOTO: A Microsoft logo is seen a day after Microsoft Corp's $26.2 billion purchase of LinkedIn Corp, in Los Angeles, California, US June 14, 2016. REUTERS/Lucy Nicholson

Mitigation

Until yesterday, when updates , there had been no fix for the zero-day vulnerability in Internet Explorer. Microsoft had only released some mitigations, which removed the permission for jscript.dll, so that attackers could not exploit the vulnerability. However, there were some limitations.

With the February Patch, Microsoft has released official security updates for the CVE-2020-0674 | Scripting Engine Memory Corruption vulnerability. With these updates, users can fully protect their systems.

All Internet Explorer users are urged to immediately update vulnerable systems, because this particular zero-day vulnerability is very dangerous.

In the table below, you can find links to the pages that detail the changes as well as the Microsoft Update catalog for each security update.

Product PlatformArticleDownload
Internet Explorer 10Windows Server 20124537814Monthly Rollup
4537767IE Cumulative
Internet Explorer 11Windows 10 Version 1803 for 32-bit Systems4537762Security Update
Internet Explorer 11Windows 10 Version 1803 for x64-based Systems4537762Security Update
Internet Explorer 11Windows 10 Version 1803 for ARM64-based Systems4537762Security Update
Internet Explorer 11Windows 10 Version 1809 for 32-bit Systems4532691Security Update
Internet Explorer 11Windows 10 Version 1809 for x64-based Systems4532691Security Update
Internet Explorer 11Windows 10 Version 1809 for ARM64-based Systems4532691Security Update
Internet Explorer 11Windows Server 20194532691Security Update
Internet Explorer 11Windows 10 Version 1909 for 32-bit Systems4532693Security Update
Internet Explorer 11Windows 10 Version 1909 for x64-based Systems4532693Security Update
Internet Explorer 11Windows 10 Version 1909 for ARM64-based Systems4532693Security Update
Internet Explorer 11Windows 10 Version 1709 for 32-bit Systems4537789Security Update
Internet Explorer 11Windows 10 Version 1709 for x64-based Systems4537789Security Update
Internet Explorer 11Windows 10 Version 1709 for ARM64-based Systems4537789Security Update
Internet Explorer 11Windows 10 Version 1903 for 32-bit Systems4532693Security Update
Internet Explorer 11Windows 10 Version 1903 for x64-based Systems4532693Security Update
Internet Explorer 11Windows 10 Version 1903 for ARM64-based Systems4532693Security Update
Internet Explorer 11Windows 10 for 32-bit Systems4537776Security Update
Internet Explorer 11Windows 10 for x64-based Systems4537776Security Update
Internet Explorer 11Windows 10 Version 1607 for 32-bit Systems4537764Security Update
Internet Explorer 11Windows 10 Version 1607 for x64-based Systems4537764Security Update
Internet Explorer 11Windows Server 20164537764Security Update
Internet Explorer 11Windows 7 for 32-bit Systems Service Pack 14537820Monthly Rollup
4537767IE Cumulative
Internet Explorer 11Windows 7 for x64-based Systems Service Pack 14537820Monthly Rollup
4537767IE Cumulative
Internet Explorer 11Windows 8.1 for 32-bit systems4537821Monthly Rollup
4537767IE Cumulative
Internet Explorer 11Windows 8.1 for x64-based systems4537821Monthly Rollup
4537767IE Cumulative
Internet Explorer 11Windows 8.14537821Monthly Rollup
Internet Explorer 11Windows Server 2008 R2 for x64-based Systems Service Pack 14537820Monthly Rollup
4537767IE Cumulative
Internet Explorer 11Windows Server 20124537814Monthly Rollup
4537767IE Cumulative
Internet Explorer 11Windows Server 2012 R24537821Monthly Rollup
4537767IE Cumulative
Internet Explorer 9Windows Server 2008 for x64-based Systems Service Pack 24537810Monthly Rollup
4537767IE Cumulative
Internet Explorer 9Windows Server 2008 for 32-bit Systems Service Pack 24537810Monthly Rollup
4537767IE Cumulative
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS