Skip to main content

Microsoft warns of new security flaw in Internet Explorer

Microsoft has issued a new security advisory, warning the public of a security loophole that could expose the 900 million or so users of Internet Explorer to risks of information theft and, possibly, the risk of a total machine hijacking.

The vulnerability is found in all versions of Windows, but only appears to manifest itself through Microsoft’s Internet Explorer Web browser. The protocol handler MIME Encapsulation of Aggregate HTML (MHTML), which is used by certain applications for document rendering, is at the heart of the rather serious security flaw. A MHTML exploit would appear very similar to an server-side cross-site-scripting (XSS) attack, a vulnerability that injects malicious client-side script into Web pages.

“For instance, an attacker could construct an HTML link designed to trigger a malicious script and somehow convince the targeted user to click it,” Microsoft’s Angela Gunn said in a blog post. “When the user clicked that link, the malicious script would run on the user’s computer for the rest of the current Internet Explorer session.” The script could then be used to gather users’ information or display malicious content.

Microsoft says its working on a security fix that will address the glitch, but in the meantime suggests that all Windows users — especially those that also use Internet Explorer —  download a “Fix-It Package” that blocks any attempts to take advantage of the vulnerability. Microsoft says it is not aware of any attempts to exploit the loophole. Of all major browsers, Microsoft’s Internet Explorer and Opera Software’s Opera browser are the only that offer native support for MHTML. Mozilla’s Firefox browser offers support for MHTML through a plug-in.

Editors' Recommendations

Aemon Malone
Former Digital Trends Contributor
Microsoft Copilot sounds great. Here’s why I definitely won’t use it
Using Windows 11 copilot to summarize a document.

A lot of Microsoft's September event was dedicated to Copilot, Bing Chat, and other AI-driven features. In a way, the updates made to laptops like the Surface Laptop Studio 2 almost felt like an afterthought. It was a real AI fest -- and no wonder, as Microsoft has certainly created something bragworthy.

Despite how impressive Copilot seems to be, I can't see myself actually using it. It's a neat party trick, but my concerns with the AI outweigh any upsides it might have.
AI everywhere

Read more
Microsoft accidentally released 38TB of private data in a major leak
A large monitor displaying a security hacking breach warning.

It’s just been revealed that Microsoft researchers accidentally leaked 38TB of confidential information onto the company’s GitHub page, where potentially anyone could see it. Among the data trove was a backup of two former employees’ workstations, which contained keys, passwords, secrets, and more than 30,000 private Teams messages.

According to cloud security firm Wiz, the leak was published on Microsoft’s artificial intelligence (AI) GitHub repository and was accidentally included in a tranche of open-source training data. That means visitors were encouraged to download it, meaning it could have fallen into the wrong hands again and again.

Read more
This new Windows 11 feature is a great addition for PC gamers
HP Pavilion Gaming Desktop on a desk with two monitors nearby displaying games and a keyboard and headset to the side.

Microsoft is developing improved controls for Windows 11 users, aiming to change how the operating system manages high refresh rate monitors. The latest Windows 11 preview build includes the ability to automatically adjust the refresh rate on multiple monitors based on what content is being displayed.

“We have improved refresh rate logic to allow different refresh rates on different monitors, depending on the refresh rate for each monitor and content shown on the screen. This will help most with refresh rate-dependent multitasking, like playing a game and watching a video at the same time,” said Microsoft’s Amanda Langowski and Brandon LeBlanc in a blog post announcing the new preview build.

Read more