Skip to main content

It's official: Older versions of Internet Explorer are now at risk


Microsoft this week made good on a 2014 promise and withheld security updates from users of older versions of the company's Internet Explorer (IE) browser.

All Windows users still running IE7 or IE8, and those running IE9 on any other edition of Windows but Vista, as well as those using IE10 on anything but Windows Server 2012, did not receive the patches Microsoft distributed Tuesday to systems equipped with the newer IE11 or Edge browsers.

As is its practice, Microsoft issued a single, cumulative update for IE on Feb. 9. The update, labeled MS16-009, included fixes for 13 vulnerabilities.

While Microsoft did not spell out which fixes were not given to older copies of IE, it isn't difficult to pinpoint those unsent.

Of the 13 vulnerabilities patched by MS16-009, nine affected every version of IE that is still supported, including IE9 on Windows Vista and IE10 on Windows Server 2012. Because different versions of Microsoft's browser share large amounts of code -- that was one of the primary reasons the Redmond, Wash. company has dead-ended IE and started over with Edge -- it's almost certain that the nine vulnerabilities also exist in IE7 and IE8, and in IE9 and IE10 on Windows editions ineligible for patching.

In other words, more than two-thirds of the vulnerabilities patched by Microsoft on Tuesday probably exist in the retired IE versions.

The danger with known, but unpatched vulnerabilities is significant: Cyber criminals regularly parse updates and compare "before" and "after" code to determine what was changed. They then use that information to investigate further in an attempt to reverse-engineer the patch to find the underlying vulnerability. Once the bug has been identified, they craft an exploit to successfully hack unpatched software, knowing that not everyone updates immediately.

In this case, the vulnerability found in, say, IE9 on Vista -- which was patched this week -- may give them insight into the location of the bug in the older IE8. From there, they can create an exploit for the unpatched browser.

Cyber criminals will have motivation to do this work, at least temporarily, because a large number of IE users worldwide are still running the now-retired versions. According to data from analytics vendor Net Applications, about a third of those running IE last month used a version that has stopped receiving security updates.

Microsoft declared the early retirement of IE7 and IE8, and partial retirement of IE9 and IE10, in August 2014, when it told customers they must upgrade to the latest browser available for their OS by Jan. 12, 2016. For most users, the latest version is IE11.

Comments

Popular posts from this blog

Court Convicts Son, Mother, Girlfriend for $902,935 Internet Fraud in Asaba

  Justice F. A. Olubanjo of the Federal High Court sitting in Asaba, Delta State on Thursday, July 22 convicted and sentenced Gift Kenneth, Dora Animam and Spice Chimzi Dandy Igwe to prison for internet-related fraud. Kenneth, his biological mother, Animam and girlfriend, Igwe were arraigned on one count charge each by the Benin Zonal Office of the Economic and Financial Crimes Commission for offences bordering on impersonation and obtaining by false pretences. They were said to have conspired to defraud an American lady, Lucinda Ann Garnes Henrichson of an aggregate sum of $902,935 The charge against Gift Kenneth reads: "that you Gift Kenneth (a.k.a Raymond Carl Eric ) on or about the year 2018 and 2019 at Agbor within the jurisdiction of this Honourable Court did fraudulently impersonate the identity of one Raymond Carl Eric by which you propose an Infrastructural Investment Project to one Lucinda Ann Garnes Henrichson living in Texas, United States of America and thereby indu

Eden Hazard: 'I would consider Real Madrid offer'

Chelsea forward Eden Hazard has admitted that he would have to listen if Real Madrid were to come forward with a bid for him. The Belgium international was a key figure as the Blues won the Premier League title in 2016-17, scoring 16 goals in 36 games. Hazard, who has regularly been linked with a move to the Bernabeu, was asked by Sky Sports News about his thoughts on a potential move to Los Blancos. He replied: "Of course, I would consider it if Madrid made an offer. I am keen to win trophies. It would be great to win the Champions League. But Chelsea's goal is to win the Champions League as well. Honestly, I do not know what will happen. "I only know that I still have a contract with Chelsea for three seasons and that we just had an amazing 2016-17 campaign. We want to continue on this path and want to build on this in the Champions League. "I am feeling very well at Chelsea. But you never know what will happen. I have not met with the board yet to discuss a new

Shocking video shows angry father beating teenage daughter in Ebonyi State after he caught her having sex with lover

Disturbing video emerged on social media which shows an angry father beating his daughter, a high school student after he caught her having sex with a man in their home. He even gave people around permission to film the scene. The incident reportedly happened yesterday, July 28 in Uburu, Ohaozara, Ebonyi state. I'm sharing the photos because you can't tell who they are from looking at the photos. See them after the cut...