Microsoft knows about an actively exploited bug in Internet Explorer on all Windows versions, but likely won't have a fix until the next Patch Tuesday on Feb 11
Microsoft has confirmed a security flaw affecting Internet Explorer is currently being used by hackers, but that it has no immediate plans to fix.
Context & Ripple Effects
Microsoft has confirmed an Internet Explorer flaw that attackers are already using, but is routing the fix through its regular February 11 Patch Tuesday rather than shipping an emergency update. That is a deliberate contrast with its own playbook: the company has twice broken cadence for IE when exploitation was live, with an emergency patch in August 2015 and an out-of-band update in December 2018.
The decision matters because the affected surface is every supported Windows version, and because the same tension — calendar-driven patching versus an actively exploited legacy browser — recurs across the corpus, from a 2015 remote code execution fix to an August 2020 batch that patched another actively exploited IE RCE.
First-order effects
- Windows users and enterprises running IE-dependent line-of-business apps are exposed to known attacks for roughly three weeks until Feb 11, with mitigation left to defensive configuration and third-party protections.
- Microsoft's security response team absorbs the reputational cost of confirming exploitation while withholding a fix, after having set the expectation with prior out-of-band releases that live exploitation justifies breaking the cycle.
Second-order effects
- Security vendors and enterprise defenders fill the gap with detections and workarounds, shifting short-term reliance toward third parties while Microsoft holds to the schedule.
- Each confirmed-but-unpatched window strengthens customer arguments for more frequent or emergency patching, pressuring the Patch Tuesday model that Microsoft has already bent twice for IE.
Third-order effects
- If the pattern holds — in-cycle fixes for exploited IE flaws in 2015, 2020, and again here — legacy browser code becomes a standing attack surface whose remediation pace is set by release logistics rather than threat severity, foreshadowing the retirement pressure on IE that later coverage of IE-engine zero-days abused via Office keeps alive.
- The recurring trade-off between predictable patching and urgent response points toward structural change in how platform vendors handle actively exploited vulnerabilities, though whether that means faster emergency channels or broader mitigation defaults remains genuinely open.
The trend: Microsoft's handling of actively exploited Internet Explorer flaws shows a platform vendor repeatedly weighing its fixed monthly patch cadence against live attacks on legacy browser code it can no longer quickly retire.