New zero day flaw hits Microsoft’s Internet Explorer
Yet another security vulnerability has been confirmed in Microsoft’s browser.
Microsoft confirmed this week another zero day security flaw had hit Internet Explorer (IE), affecting all versions of the browser.
In a security advisory released late yesterday, the software giant confirmed a remote code execution vulnerability which was a result of an invalid flag reference in IE.
The issue had already been taken advantage of, as Microsoft admitted to being "aware of targeted attacks." However, the company has yet to confirm a fix for the problem.
"We will continue to monitor the threat environment and update this advisory if this situation changes," the advisory said.
"On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs."
The usual advice has been given to customers of ensuring your security software is up to date and to upgrade to the latest version of the browser, IE8.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Jennifer Scott is a former freelance journalist and currently political reporter for Sky News. She has a varied writing history, having started her career at Dennis Publishing, working in various roles across its business technology titles, including ITPro. Jennifer has specialised in a number of areas over the years and has produced a wealth of content for ITPro, focusing largely on data storage, networking, cloud computing, and telecommunications.
Most recently Jennifer has turned her skills to the political sphere and broadcast journalism, where she has worked for the BBC as a political reporter, before moving to Sky News.
-
AI is creating a 'two-track' labor marketNews Research from PwC has found that as many entry-level functions are replaced by AI, organizations are looking for leadership and creativity
-
Anthropic suspends Fable and Mythos systems "for all users"News Despite complying with the government, Anthropic suggests it's only a "potential narrow, non-universal jailbreak"
-
AI is shrinking attack windows, and it’s forcing a complete rethink of cyber resilience – here’s how organizations can prepareNews Commvault has urged companies to improve their business continuity and resilience plans in the face of flaws spotted by AI
-
Anthropic targets vulnerability detection gains with Claude Security public beta — here's what users can expectNews The Claude Mythos developer is aiming for a more limited approach to cyber tooling for public consumption
-
Researchers warn millions of RDP and VNC servers are wide open to exploitationNews Researchers at Forescout spotted millions of RDP and VNC servers exposed online
-
Brace yourselves for a vulnerability explosion, Forescout warnsNews AI advances are helping identify software flaws at record pace and scale, but that's not the good news some would think
-
Ubuntu vulnerability exposes enterprises to root escalation, complete system compromiseNews The high-severity Ubuntu vulnerability allows an unprivileged local attacker to escalate privileges through the interaction of two standard system components
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
Millions of developers could be impacted by flaws in Visual Studio Code extensions – here's what you need to know and how to protect yourselfNews The VS Code vulnerabilities highlight broader IDE security risks, said OX Security
-
CVEs are set to top 50,000 this year, marking a record high – here’s how CISOs and security teams can prepare for a looming onslaughtNews While the CVE figures might be daunting, they won't all be relevant to your organization
