Skip to main content

Microsoft warns of new security flaw in Internet Explorer

Microsoft has issued a new security advisory, warning the public of a security loophole that could expose the 900 million or so users of Internet Explorer to risks of information theft and, possibly, the risk of a total machine hijacking.

The vulnerability is found in all versions of Windows, but only appears to manifest itself through Microsoft’s Internet Explorer Web browser. The protocol handler MIME Encapsulation of Aggregate HTML (MHTML), which is used by certain applications for document rendering, is at the heart of the rather serious security flaw. A MHTML exploit would appear very similar to an server-side cross-site-scripting (XSS) attack, a vulnerability that injects malicious client-side script into Web pages.

“For instance, an attacker could construct an HTML link designed to trigger a malicious script and somehow convince the targeted user to click it,” Microsoft’s Angela Gunn said in a blog post. “When the user clicked that link, the malicious script would run on the user’s computer for the rest of the current Internet Explorer session.” The script could then be used to gather users’ information or display malicious content.

Microsoft says its working on a security fix that will address the glitch, but in the meantime suggests that all Windows users — especially those that also use Internet Explorer —  download a “Fix-It Package” that blocks any attempts to take advantage of the vulnerability. Microsoft says it is not aware of any attempts to exploit the loophole. Of all major browsers, Microsoft’s Internet Explorer and Opera Software’s Opera browser are the only that offer native support for MHTML. Mozilla’s Firefox browser offers support for MHTML through a plug-in.

Editors' Recommendations

Aemon Malone
Former Digital Trends Contributor
A major Windows update just launched. Here’s what’s new
Person using Windows 11 laptop on their lap by the window.

Microsoft has just announced the latest update to Windows 11, which brings the operating system up to version 23H2. This is a cumulative update that comes with some of the most exciting features already announced in September, including Copilot, and brings some changes to Teams, among other things. Here's what's new and how to get it on your own PC.

When Microsoft first announced Copilot during its September event, many thought that it'd be available right away -- and it was, but not widely. Now, with the 23H2 update, Copilot should be downloaded and toggled on by default, alongside everything else that was announced during the Surface event. Some new things are on the way, too.

Read more
Microsoft Copilot sounds great. Here’s why I definitely won’t use it
Using Windows 11 copilot to summarize a document.

A lot of Microsoft's September event was dedicated to Copilot, Bing Chat, and other AI-driven features. In a way, the updates made to laptops like the Surface Laptop Studio 2 almost felt like an afterthought. It was a real AI fest -- and no wonder, as Microsoft has certainly created something bragworthy.

Despite how impressive Copilot seems to be, I can't see myself actually using it. It's a neat party trick, but my concerns with the AI outweigh any upsides it might have.
AI everywhere

Read more
Microsoft accidentally released 38TB of private data in a major leak
A large monitor displaying a security hacking breach warning.

It’s just been revealed that Microsoft researchers accidentally leaked 38TB of confidential information onto the company’s GitHub page, where potentially anyone could see it. Among the data trove was a backup of two former employees’ workstations, which contained keys, passwords, secrets, and more than 30,000 private Teams messages.

According to cloud security firm Wiz, the leak was published on Microsoft’s artificial intelligence (AI) GitHub repository and was accidentally included in a tranche of open-source training data. That means visitors were encouraged to download it, meaning it could have fallen into the wrong hands again and again.

Read more