Skip to main content

Microsoft issues fix for 0-day vulnerability in Internet Explorer 9 and 10

microsoft issues fix for 0 day vulnerability in internet explorer 9 and 10 ie
Image used with permission by copyright holder

If you use either Internet Explorer 9 or Internet Explorer 10, you might like to know that a new vulnerability has been discovered that affects users of both versions of Microsoft’s browser, according to Mircosoft’s Security TechCenter page. Fortunately, though Microsoft has not yet issued a full patch for this problem, they have at least put out a fix that aims to prevent hackers to use this exploit to target you while surfing the web using IE. 

Here’s what Microsoft had to say about the security hole in IE 9 and IE 10.

“The vulnerability is a remote code execution vulnerability. The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.”

How to fix the 0-day vulnerability in Internet Explorer 9 and Internet Explorer 10

While Microsoft works on a long-term fix, users of IE 9 and IE 10 can safeguard themselves by heading over to this Microsoft page and following the instructions under the “Fix it for me” section to apply the “MSHTML shim workaround.” Microsoft advises that increased memory usage could occur once the fix is applied, but also notes that this should subside once you restart Internet Explorer.

Microsoft also said that a full patch could arrive with their regularly scheduled Patch Tuesday updates, or as an out-of-cycle update. The next Patch Tuesday will take place on March 11, about two and a half weeks from now.

On a related note, a flaw in Internet Explorer 10 was recently exploited to launch attacks on visitors of a website that caters to the needs of U.S. military veterans

What do you think? Sound off in the comments below.

Editors' Recommendations

Konrad Krawczyk
Former Digital Trends Contributor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
Update Windows now — Microsoft just fixed several dangerous exploits
Person sitting and using an HP computer with Windows 11.

Microsoft has just released a new patch, and this time around, the update comes with fixes for several dangerous and actively abused vulnerabilities and exploits in Windows.

A total of 68 vulnerabilities were addressed in the patch, many of them critical. Here's what was fixed and how to make sure your Windows device is up to date.

Read more
Microsoft Surface Pro 9 vs. Surface Pro 8: here’s how they stack up
Microsoft Surface Pro 9 front view showing tablet and videoconferencing.

The Microsoft Surface Pro has spent years on our best laptops and best 2-in-1s lists. The Surface Pro 8, which represented the most significant revision to the tablet in years, maintained that spot.

Microsoft has introduced the Surface Pro 9, which retains the same basic design while updating the internals. Read on to find out if the newest Surface Pro is worth an upgrade.

Read more
Four months later, Intel CPU stability issues remain
Intel's 14900K CPU socketed in a motherboard.

It's been over four months since the first reports of instability in Intel's top CPUs started cropping up, and we are yet to see a fix. Although Intel has been working with its partners on delivering updates that would address the problem, the company itself had to admit in a recent community post that it still hasn't found the root cause.

Meanwhile, hardware testers are finding that even using Intel's recommended workarounds still ends up in crashes and unstable performance -- and the only solutions that seem to work are things that you'll have to settle for.

Read more