Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Microsoft bails out XP users with unexpected Internet Explorer zero-day flaw patch

Add as a preferred source on Google

In a surprising reversal of policy, Microsoft has decided to issue a patch for Windows XP-based users of their Internet Explorer Web browser, Reuters reports. The flaw was slated to go un-patched for Windows XP, which would have permanently left the versions of Internet Explorer that are compatible with the dated OS vulnerable to the flaw. Microsoft reportedly stated as recently as Wednesday that the bug would be left untreated for XP.

“We decided to fix it, fix it fast, and fix it for all our customers,” Microsoft spokeswoman Adrienne Hall said in a statement.

Recommended Videos

This comes after Windows XP users were warned by the U.S. Department of Homeland Security to stop using Internet Explorer because of the threat posed by the vulnerability. The DHS recommended using alternative Web browsers instead, like Google Chrome, or Mozilla Firefox.

Microsoft described the security hole as “a remote code execution vulnerability” which “could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.” Internet security firm FireEye stated today in an official blog post that hackers were using the flaw to target government, energy, defense, and financial industries. However, attacks on the latter two sectors had already been observed by FireEye.

The zero-day bug threatened Internet Explorer versions 6 through 11, though workarounds have been available for Internet Explorer 10 and Internet Explorer 11. However, those versions of the browser aren’t compatible with Windows XP. The last version of Internet Explorer that was compatible with Windows XP was IE 8, according to Microsoft’s IE system requirements pages. IE 8’s “lifecycle start date” was June 17, 2009.

Microsoft ceased supporting Windows XP on April 8. However, should additional threats like this emerge, it’ll be interesting to see whether Microsoft will take similar steps to protect Windows XP users from such dangers.

 
Konrad Krawczyk
Former Computing Editor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
The Mac Pro nearly received an M3 Extreme chip twice as powerful as M3 Ultra
High production costs likely killed Apple’s M3 Extreme plans
Apple's Mac Pro on a table at a press event.

Apple discontinued the Mac Pro earlier this year, ending a 20-year run for a computer that once represented the very best of the company’s desktop lineup. However, Apple reportedly had much bigger plans for the machine before ultimately replacing it with the Mac Studio.

According to Bloomberg’s Mark Gurman, Apple developed an M3 Extreme chip that could have offered twice as many CPU and GPU cores as the M3 Ultra. The processor was intended to sit above the Ultra tier and could have finally given the Mac Pro the performance advantage it badly needed. Apple eventually abandoned the chip due to concerns over production costs and limited demand for such an expensive machine.

Read more
Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem
Researchers discover AI attack that rewrites an assistant's long-term memory
Chatbot on a smartphone.

Large language models are getting better at remembering us. Whether it's your preferred writing style, recurring tasks, shopping habits or project deadlines, AI assistants are increasingly storing long-term memories to make future conversations feel more personal and useful. But according to new research, that same feature could become one of AI's biggest security vulnerabilities.

Researchers from New Mexico State University have demonstrated a new attack called GhostWriter, capable of secretly planting false memories inside AI agents. Rather than stealing information outright, the attack manipulates what an AI remembers, potentially causing it to make dangerous decisions long after the original attack has taken place.

Read more
This experiment shows how easy it is to poison an open-weight AI model for under $100
This research raises new doubts about trusting open weight AI models.
Computer, Electronics, Laptop

Open-weight AI models have been having a moment lately. Just this month, Moonshot's massive Kimi K3 model landed close behind Claude Fable 5 and GPT 5.6 Sol in several benchmarks, all while remaining fully open-weight and downloadable by anyone.

However, Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University and staff security advocate at Semgrep, managed to poison an open-weight model and proved how easily that openness can be turned against you (via The Register).

Read more