Categories: Breaking NewsSecurity

Critical Zero-Day flaw – Microsoft Pushes Emergency IE Patch

Microsoft has pushed an emergency patch to remediate a zero-day vulnerability in Internet Explorer that is actively being exploited in-the-wild.

Today, August 18th, 2015, Microsoft released an emergency patch after being notified of a critical vulnerability in all supported versions of Internet Explorer. All versions of Microsoft Internet Explorer from IE7 to IE11 are affected by this zero-day vulnerability.

The vulnerability, referenced by CVE as CVE-2015-2502 or by Microsoft as MS15-093, has been described by Brian Krebsas a “browse-and-get-owned” vulnerability. What this means is that this zero-day vulnerability is essentially exploited in “drive-by” fashion; no user intervention other than browsing a malicious web page will result in the infection of users utilizing vulnerable versions of IE.

A vulnerability of this criticality level, with a delivery mechanism that requires no more than a simple click or re-direct has the capability of causing a very large quantity of damage.

The zero-day flaw is Actively Being Exploited In-the-Wild

According to Qualys‘ CTO Wolfgang Kandek, this vulnerability is currently being exploited in-the-wild. The delivery mechanisms utilized by threat actors looking to exploit this vulnerability and their methods of increasing their damaging potential can be inferred based on past vulnerability disclosures, however, Qualys has stated that the following methods are being utilized by attackers to carry out these two goals:

  • Malvertising
  • Compromise and Infection of Once-Legitimate Websites (i.e. vulnerable WordPress sites)
  • Deployment of Dedicated Attack Websites & Utilizing Blackhat SEO Tactics to Boost Site Traffic
  • Phishing Methods Delivering URLs to the Malicious Webpage to Target Users

As we have observed in the past with the somewhat recent release of several zero-day vulnerabilities in popular software (e.g. Adobe Flash Player), it is only a matter of time before exploit kit integration begins. We should expect to see this vulnerability integrated in top exploit kits very soon; I would be surprised if some of the top players do not integrate this vulnerability into their arsenal within the next 24 hours.

Additionally, even if you do not use Microsoft Internet Explorer, it is recommended that you update the version of IE installed on your (Windows) device.

“Windows users should install the patch whether or not they use IE as their main browser, as IE components can be invoked from a variety of applications, such as Microsoft Office.” – Brian Krebs

Note: Windows 10’s Edge browser is not affected by this vulnerability.

Where to Retrieve the Emergency Patch

The emergency patch can be downloaded and install both via Windows Update as well as from Microsoft’s website.

Sources

Brian Krebs for his fast reporting (as always)
Qualys for reporting on this vulnerability and patch release as well as their research

About the Author Michael Fratello

Michael Fratello is a Security Engineer employed by CipherTechs, Inc., a privately held information security services provider located in downtown Manhattan, New York.  Specializing in Penetration Testing and Digital Forensics, Michael, a St. John’s University graduate majoring in Computer Security Systems, has developed a passion for information security and often spends his free time studying, programming, and researching the exponentially growing number of threats found in-the-wild today.

Edited by Pierluigi Paganini

Pierluigi Paganini

(Security Affairs – Zero-Day, Microsoft)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Leader of Qakbot cybercrime network indicted in U.S. crackdown

The U.S. indicted Russian Rustam Gallyamov for leading the Qakbot botnet, which infected 700K+ devices…

1 minute ago

Operation RapTor led to the arrest of 270 dark web vendors and buyers

Law enforcement operation codenamed 'Operation RapTor' led to the arrest of 270 dark web vendors…

1 day ago

Chinese threat actors exploited Trimble Cityworks flaw to breach U.S. local government networks

A Chinese threat actor, tracked as UAT-6382, exploited a patched Trimble Cityworks flaw to deploy…

1 day ago

U.S. CISA adds a Samsung MagicINFO 9 Server flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Samsung MagicINFO 9 Server vulnerability to its…

2 days ago

New Signal update stops Windows from capturing user chats

Signal implements new screen security on Windows 11, blocking screenshots by default to protect user…

2 days ago

Law enforcement dismantled the infrastructure behind Lumma Stealer MaaS

Microsoft found 394,000 Windows systems talking to Lumma stealer controllers, a victim pool that included…

2 days ago