//Internet Explorer Zero-Day Vulnerability Unfixed

Internet Explorer Zero-Day Vulnerability Unfixed

Share with friends

On January 17, 2020, Microsoft released a warning of a “zero-day” vulnerability in Internet Explorer. The flaw exists within the scripting engine and how it handle’s objects within IE memory.

If successfully exploited, the vulnerability could allow the attacker to take control of an affected system. The attacker would then be enabled to “install programs; view, change, or delete data; or create new accounts with full user rights”.

How does such an attacker draw out a victim? Microsoft painted the following scenario: “…an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website, for example, by sending an email.”

Therefore, until a resolution or patch is released, if one is released, it may be advisable for a user to use a more secure browser. If using Internet Explorer is absolutely unavoidable, a user should not open e-mails or click on links with a destination they are unfamiliar with.