Microsoft knows about an actively exploited bug in Internet Explorer on all Windows versions but likely won't have a fix until the next Patch Tuesday on Feb. 11
Context & Ripple Effects
This is a familiar dilemma for Microsoft's security response: an Internet Explorer flaw is being exploited in the wild now, but the fix rides the regular February Patch Tuesday cycle rather than shipping immediately. The corpus shows Microsoft has taken both paths before — it issued an emergency out-of-band IE update in December 2018 when attackers were hijacking machines, yet also let an actively exploited IE remote code execution flaw wait for the monthly cycle before fixing it among 17 critical flaws and two zero-days in August 2020.
The stakes are elevated because IE's engine keeps resurfacing as an attack surface even outside the browser — a year later Microsoft warned of an actively abused zero-day in IE's browser engine targeting Office applications. Every week between disclosure and Patch Tuesday is exposure time for the large installed base of Windows machines that still render IE-based content.
First-order effects
- Windows users and enterprises running IE-dependent line-of-business apps face roughly three weeks of known, active exploitation with no vendor fix, since Microsoft does not expect to patch before the Feb. 11 Patch Tuesday.
- Security teams must compensate in the interim with workarounds and detection rather than remediation, shifting the burden of protection from Microsoft to defenders during the gap.
Second-order effects
- The precedent of Microsoft's 2015 and 2018 emergency IE patches puts pressure on the company to break cadence and ship an out-of-band fix if exploitation widens before Feb. 11.
- Attackers get a public countdown clock: disclosure without a patch concentrates targeting on the flaw for the three-week window, raising the odds more campaigns surface before the fix lands.
Third-order effects
- If the pattern holds — monthly cadence defaulting over emergency response for actively exploited IE flaws — legacy browser components stay a standing attack surface long past their intended retirement, pushing enterprises to finally strip IE dependencies from critical apps.
- Repeated gaps between disclosure and patching strengthen the case for faster emergency-update norms across the industry, since attackers demonstrably exploit the fixed schedule.
The trend: Microsoft's monthly Patch Tuesday rhythm keeps leaving actively exploited Internet Explorer vulnerabilities unpatched for weeks, with out-of-band releases reserved for moments of acute pressure.