Skip to main content

Microsoft’s January security update neglects patch for IE zero-day vulnerability

Image used with permission by copyright holder

Following normal routine, Microsoft gave advance notice on Thursday of the seven security updates being released this coming Patch Tuesday, including one rated critical for protecting Windows 8 and Windows RT. All in all, the bundle will address 12 different vulnerabilities. Yet conspicuously missing – as security experts were quick to point out – was a fix for an Internet Explorer zero-day exploit that has recently been plaguing users of IE6, IE7, and IE8.

Although the IE vulnerability alarmed Microsoft enough to issue a security advisory about it last Saturday, the company has since downplayed its seriousness, claiming it affected only a limited number of customers. However, it compromised several websites, including those of Capstone Turbine, a gas turbine manufacturer, and the Council on Foreign Relations, a foreign-policy think tank. When hacked, these websites became unsafe for visitors using IE6, IE7, and IE8, installing unwanted malware on users’ computers and attempting to steal personal data.

Fortunately, there remains a number of solutions for the IE zero-day vulnerability. Newer versions of Internet Explorer do not share this security weakness, so Microsoft is encouraging users to upgrade to IE9 or IE10 if possible. Unfortunately, those running Windows XP or earlier Windows operating systems are unable to upgrade to IE9 and IE10.

Image used with permission by copyright holder

For these customers, Microsoft has provided a single-click “Fix it” workaround that will take care of the security vulnerability. Finally, if users see a major increase in the number of attacks exploiting this vulnerability, Microsoft may release a special “out-of-band,” or off-schedule, security update prior to its next Patch Tuesday, which isn’t set to take place until February 12. Of course, you can always try out the latest version of Chrome in the meantime. 

Editors' Recommendations

Mika Turim-Nygren
Former Digital Trends Contributor
Mika Turim-Nygren writes about technology, travel, and culture. She is a PhD student in American literature at the University…
The Meta Quest 3 will get an exciting new type of app
A Windows app extends into 3D space via a Meta Quest 3 VR headset.

A Windows app extends into 3D space via a Meta Quest 3 VR headset. Microsoft

At Build 2024, Microsoft announced it partnered with Meta to extend Windows apps into 3D space with the help of a Quest VR headset. When working on physical objects, it’s important to have spatial awareness of components.

Read more
How to build a PC from scratch: A beginner’s guide
Installing RAM in a desktop PC.

Building a PC for the first time, or even the second or third time, can feel a little intimidating. But one of the best parts about building a computer is that, for the most part, the parts fit where they should, and don't fit where they shouldn't. A graphics card will fit in the graphics card slot, and good luck putting the CPU in the wrong socket.

With a little care, time, and this handy guide, you can build a PC without hassle. We're here to walk you through it.

Read more
Microsoft just made Paint relevant again
Person using Windows 11 laptop on their lap by the window.

The controversial Recall feature has grabbed all the headlines from Microsoft’s Copilot+ announcements yesterday, but this new AI feature is also making Paint relevant again.

It’s called Cocreator, and it’s a new AI feature that can turn your quick sketch, augmented by text, into a much more realistic and impressive image. The exciting thing is that it does all this in real time. It might not get it right the first time, so you'll need patience, and the more details you give about what you want in the image, the better.

Read more