Microsoft rushes to patch IE, Visual Studio
Microsoft is set to issue two out-of-band patches tomorrow, including a new critical update for Internet Explorer.


Microsoft will release two emergency security patches tomorrow afternoon.
Microsoft normally issues security fixes as part of its monthly patching cycle, but the two fixes for Internet Explorer and Visual Studio will arrive out-of-band.
"While we can't go into specifics about the issue prior to release, we can say that the Visual Studio bulletin will address an issue that can affect certain types of applications," said Mike Reavey in a post on the Microsoft Security Research Centre blog.
"The Internet Explorer bulletin will provide defense-in-depth changes to Internet Explorer to help provide additional protections for the issues addressed by the Visual Studio bulletin," he added.
Reavey added that the IE update will fix additional critical flaws in the browser that are unrelated to the Visual Studio issue, which were reported "privately and responsibly."
Microsoft advised users not to be too scared by the rush, as any customers who have the latest security updates are safe from the "known attacks" related to the security release.
Full details on the security bulletin can be found here.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
What is polymorphic malware?
Explainer Polymorphic malware constantly changes its code to avoid detection, making it a top cybersecurity threat that demands advanced, behavior-based defenses
-
Outgoing Kaseya CEO teases "this is just the beginning" for the company
Opinion We spoke to Fred Voccola who remains a key figurehead at the firm as it enters its next chapter...
-
Vulnerability management complexity is leaving enterprises at serious risk
News Fragmented data and siloed processes mean remediation is taking too long
-
Beat cyber criminals at their own game
Whitepaper A guide to winning the vulnerability race and protection your organization
-
Same cyberthreat, different story
Whitepaper How security, risk, and technology asset management teams collaborate to easily manage vulnerabilities
-
Three steps to transforming security operations
Whitepaper How to be more agile, effective, collaborative, and scalable
-
Should your business start a bug bounty program?
In-depth Big tech firms including Google, Apple and Microsoft offer bug bounty programs, but can they benefit smaller businesses too?
-
Accessing the XDR realm
Whitepaper A guide for MSPs to unleash modern security
-
Why zero trust strategies fail
In-depth Zero Trust is the gold standard for organizations in protecting systems from cyber attacks, but there are many common implementation pitfalls businesses must avoid
-
Sitecore XP RCE flaw is being actively exploited, ACSC warns
News The vulnerability was fixed last month but hackers are now moving against patching laggards