Unsolved
This post is more than 5 years old
5 Journeyman
•
15.6K Posts
•
45K Points
0
795
January 18th, 2020 03:00
UNPATCHED 0-day exploit in IE
The following was copied/pasted from https://www.zdnet.com/article/microsoft-warns-about-internet-explorer-zero-day-but-no-patch-yet/
Microsoft has published a security advisory today about an Internet Explorer (IE) vulnerability that is currently being exploited in the wild -- a so-called zero-day.
The company's security advisory (ADV200001) currently only includes workarounds and mitigations that can be applied in order to safeguard vulnerable systems from attacks.
At the time of writing, there is no patch for this issue. Microsoft said it was working on a fix, to be released at a later date.
======================
The advisory https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200001 contains a workaround to mitigate this exploit, restricting the memory corruption bug in IE's scripting engine -- the browser component that handles JavaScript code. Be advised that implementing these steps might result in reduced functionality for components or features that rely on jscript.dll.
Furthermore, stress that by default, IE11, IE10, and IE9 use Jscript9.dll which is not impacted by this vulnerability. This vulnerability only affects certain websites that utilize jscript as the scripting engine.
That being the case, and since I don't use IE any more, I' m just gonna wait-it-out until Microsoft releases its official patch.


ky331
5 Journeyman
•
15.6K Posts
•
45K Points
0
January 27th, 2020 04:00
From https://www.bleepingcomputer.com/news/security/microsofts-ie-zero-day-fix-is-breaking-windows-printing/ :
Microsoft's mitigation has caused the following issues:
RoHe
12 Elder
•
45.2K Posts
•
172.6K Points
0
January 27th, 2020 12:00
The cure sounds worse than the disease...!