Microsoft Updates IE Zero Day Vulnerability Workarounds

By Peter Bernstein April 30, 2014

Microsoft has not issued an “all clear” for us to go back to surfing the web using the various versions of its Internet Explorer (IE) browser which recently was exposed as being vulnerable to nasty zero-day cyber attacks.  However, Microsoft is making progress on helping IT departments mitigate the risks of being compromised. They have updated the workaround section of their original advisory on the problem.

As has been noted since the vulnerability was discovered, while in theory all versions of IE could be targets for being compromised, thus far the bad guys have focused their attention on the most popularly used versions of IE, versions 9, 10 and 11, and have done so leveraging the nearly ubiquitous Adobe Flash as their vector.  Indeed, as security professionals constantly observe, like bank robbing it is the place where the money is that have the weakest defenses that draw the most attention.

Scroll down to the workarounds for latest clarifications

Here is what you need to know in terms of the update to the advisory. (Details can be obtained by scrolling down to the workarounds section).

  1. On x64-based Systems, Enable Enhanced Protected Mode for Internet Explorer 10; or Enable Enhanced Protected Mode and Enable 64-bit Processes for Enhanced Protected Mode for Internet Explorer 11 . The original advisory had identified the work version of IE for which this was the solution. 
  2. The April 26 version of the advisory said to change the Access Control List (ACL) for program file, VGX.DLL, which goes by the description "Vector Graphics Rendering (VML)." The update advises that while this works, it is simpler to unregister the DLL using the command lines in the advisory, and they also give details on reversing the ACL method.

So the good news is that help is on the way. The not so good news is that instances of attacks in the wild have been occurring, and until there is a final solution, caution should be observed and IE only used if absolutely necessary.

For real personal and professional security reasons, it obviously would be imprudent to disclose any instances where you must use IE. Reality is that instances where policies and rules dictate its use are extremely common which is why they are best kept quiet. 

As the saying goes, “April showers bring May flowers,” and hopefully this rain on the Microsoft soil will yield a robust solution soon.

Edited by Maurice Nagle
Related Articles

Modern Moms Shaping Influence

By: Maurice Nagle    7/19/2018

Everyone knows Mom knows best. The internet is enabling a new era in sharing, and sparking a more enlightened, communal shopping experience. Mommy blo…

Read More

Why People Don't Update Their Computers

By: Special Guest    7/13/2018

When the WannaCry ransomware attacked companies all over the world in 2017, experts soon realized it was meant to be stopped by regular updating. Even…

Read More

More Intelligence About The New Intelligence

By: Rich Tehrani    7/9/2018

TMC recently announced the launch of three new artificial intelligence events under the banner of The New Intelligence. I recently spoke with TMC's Ex…

Read More

Technology, Innovation, and Compliance: How Businesses Approach the Digital Age

By: Special Guest    6/29/2018

Organizations must align internally to achieve effective innovation. Companies should consider creating cross-functional teams or, at a minimum, incre…

Read More

Contribute Your Brain Power to The New Intelligence

By: Paula Bernier    6/28/2018

The three events that are part of The New Intelligence are all about how businesses and service providers, and their customers, can benefit from artif…

Read More