/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft knows about an actively exploited bug in Internet Explorer on all Windows versions but likely won't have a fix until the next Patch Tuesday on Feb. 11

Zack Whittaker / TechCrunch :

TechCrunch Zack Whittaker

Context & Ripple Effects

This is a familiar dilemma for Microsoft's security response: an Internet Explorer flaw is being exploited in the wild now, but the fix rides the regular February Patch Tuesday cycle rather than shipping immediately. The corpus shows Microsoft has taken both paths before — it issued an emergency out-of-band IE update in December 2018 when attackers were hijacking machines, yet also let an actively exploited IE remote code execution flaw wait for the monthly cycle before fixing it among 17 critical flaws and two zero-days in August 2020.

The stakes are elevated because IE's engine keeps resurfacing as an attack surface even outside the browser — a year later Microsoft warned of an actively abused zero-day in IE's browser engine targeting Office applications. Every week between disclosure and Patch Tuesday is exposure time for the large installed base of Windows machines that still render IE-based content.

First-order effects

  • Windows users and enterprises running IE-dependent line-of-business apps face roughly three weeks of known, active exploitation with no vendor fix, since Microsoft does not expect to patch before the Feb. 11 Patch Tuesday.
  • Security teams must compensate in the interim with workarounds and detection rather than remediation, shifting the burden of protection from Microsoft to defenders during the gap.

Second-order effects

  • The precedent of Microsoft's 2015 and 2018 emergency IE patches puts pressure on the company to break cadence and ship an out-of-band fix if exploitation widens before Feb. 11.
  • Attackers get a public countdown clock: disclosure without a patch concentrates targeting on the flaw for the three-week window, raising the odds more campaigns surface before the fix lands.

Third-order effects

  • If the pattern holds — monthly cadence defaulting over emergency response for actively exploited IE flaws — legacy browser components stay a standing attack surface long past their intended retirement, pushing enterprises to finally strip IE dependencies from critical apps.
  • Repeated gaps between disclosure and patching strengthen the case for faster emergency-update norms across the industry, since attackers demonstrably exploit the fixed schedule.

The trend: Microsoft's monthly Patch Tuesday rhythm keeps leaving actively exploited Internet Explorer vulnerabilities unpatched for weeks, with out-of-band releases reserved for moments of acute pressure.

Discussion

  • @uscert_gov Us-Cert on x
    Microsoft has released a workaround for an Internet Explorer vulnerability being used in limited targeted attacks. Implement workarounds and apply updates when available. Read more at https://www.us-cert.gov/.... #Cyber #Cybersecurity #InfoSec
  • @jackdamn Keith on x
    If you're still using MS Internet Explorer for your web browsing, heads up. Also for Windows users, you might want to take a look at the new Chromium based Microsoft Edge browser. It's SUPER fast and has excellent tracking protection. Been testing it lately and love it. $MSFT htt…
  • @smartguitar1 Chris Smart on x
    LOL What? Who is still using Internet Explorer? Are they also listening to Realaudio? https://twitter.com/...
  • @malwarejake Jake Williams on x
    There's a 0-day in Internet Explorer being exploited in the wild that impacts Windows 7. In 2014, MS patched CVE-2014-1776 shortly after end of support for XP. Will they release a patch for Windows 7 this time? Great & timely reporting by @zackwhittaker https://techcrunch.com/...…
  • @zackwhittaker Zack Whittaker on x
    New: Microsoft says hackers are actively exploiting a bug in Internet Explorer, affecting all versions of Windows. Microsoft said it's “working on a fix,” but said patches could be weeks away. https://techcrunch.com/...