Microsoft Patches Critical Security Flaw Affecting All Versions of Windows


Microsoft has issued a critical patch for all supported versions of Windows, to address a remote code execution flaw in Internet Explorer.

If exploited, an attacker could gain access to an affected machine, gaining the same access rights as the logged-in user. From there, he or she could wreak havoc, deleting data or installing malware on the machine.

The problem lies with how Internet Explorer handles objects in memory, Microsoft said.

In order to be successful, an attacker would need to carry out a social engineering campaign to lure IE users to a specific website, or convince them to open an infected attachment. A website itself could host malicious content designed to exploit the vulnerability, or, the attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements.

In all cases, however, an attacker would have to convince users to take action, typically by getting them to click a link in an instant message or e-mail message that takes users to the attacker's Website or downloads the file.

Image via Shutterstock

"These Websites could contain specially crafted content that could exploit the vulnerabilities,” said the advisory.

Windows Vista and later, including Windows 10, are at risk; Windows server systems are also at risk, but its enhanced security mode helps to mitigate the vulnerability.

The update was issued as part of Microsoft’s monthly Patch Tuesday release. While Microsoft released six security bulletins in all, resolving a total of 19 vulnerabilities, the IE bug is the most severe. However, half of the security bulletins are critical, and all of the critical bulletins (MS15-106, MS15-108, MS15-109) are remote code execution issues affecting not just IE but also the Edge browser, VBScript & JScript Engines, Windows Shell, Office, Office Services and apps, as well as Microsoft Server Software. That’s a good chunk of the ecosystem, and admins should apply the patches as quickly as possible.

Edited by Maurice Nagle
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

Contributing Writer

Related Articles

What Is Attribute Based Access Control?

By: Contributing Writer    12/5/2023

Attribute-Based Access Control (ABAC) represents a paradigm shift in managing access rights within complex and dynamic IT environments. Unlike traditi…

Read More

Raising Value: The Strategic Gains of Embracing Bundled Result

By: Contributing Writer    12/4/2023

Where the concept of value is not just a price tag but a carefully crafted now. In a world brimming with options, the art of planned bundling has aris…

Read More

Tech Innovation in iGaming

By: Contributing Writer    11/29/2023

iGaming is one of the fastest growing industries on the internet. For those who may not be aware, iGaming refers to online casinos, online slots, poke…

Read More

8 Underrated Features of Your Mobile Device You Probably Didn't Know About

By: Contributing Writer    11/21/2023

It is easy to get lost in all the new phone releases when multiple happen yearly. Consequently, most new functions go unnoticed because people do not …

Read More

Navigating the Launch: A Step-by-Step Guide to Bringing Your Product to Market

By: Contributing Writer    11/15/2023

Embarking on the journey to bring a new product into the marketplace is an exhilarating adventure that blends the thrill of innovation with the meticu…

Read More