HomeSecurityMicrosoft rushes to "patch" a security hole in Internet Explorer - How...

Microsoft rushes to patch security hole in Internet Explorer - How hackers exploited it

microsoft-660_2

A security flaw was discovered over the weekend in the popular Internet Explorer browser, allowing hackers to exploit it and “hit”. Microsoft is rushing to “close” the security hole, which was found by a cybersecurity firm and allows hackers to remotely gain complete control of a computer. The American company has already reported that there have been isolated attacks on American companies, mainly in the defense and financial sectors.

The flaw, according to the BBC and Reuters, concerns versions 6 to 11 of Internet Explorer, which research firm NetMarketShare estimates are used on more than half (55%) of computers worldwide.

Microsoft will soon release the relevant security update for its software, but it will no longer cover Windows XP users, for whom technical support has stopped a few weeks ago (although about 25% of computers worldwide still have this older but extremely popular operating system). These users would be safer using another browser.

Cybersecurity firm FireEye Inc. said a group of hackers is already exploiting a vulnerability in Internet Explorer, conducting a malicious operation called “Hidden Fox.” FireEye did not provide further details about the identity of the hackers or their victims, but said it is continuing to investigate the matter. “It is still unclear what the motivation of the hacking group is, although it appears to be broad intelligence gathering,” a company spokesman said.

Microsoft said the vulnerability could allow an attacker to compromise a computer system, delete data, install malware, or create user accounts that give the attacker full user rights. The attacker could infect an unsuspecting user's computer if the user, deceived by a phishing email, visits a phishing website using Internet Explorer.

Neither FireEye nor Microsoft provided detailed technical information about the nature of the security flaw, apparently so as not to provide more clues to other would-be hackers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS