/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft fixes 17 critical and two zero-day flaws, including an actively-exploited RCE flaw in IE that can compromise PCs when users visit malicious sites

Microsoft says attackers have used a Windows zero-day to spoof file signatures and another RCE in the Internet Explorer scripting engine to execute code on users' devices.

ZDNet Catalin Cimpanu

Context & Ripple Effects

This Patch Tuesday is one entry in a long-running Microsoft ritual: the related coverage shows critical Internet Explorer remote code execution flaws going back to at least October 2015's Patch Tuesday, and an actively abused IE engine zero-day resurfacing in September 2021, where it was chained into attacks on Office applications.

What distinguishes this month is the pairing: alongside the exploited IE scripting-engine RCE that needs only a malicious website visit, attackers were also using a Windows zero-day to spoof file signatures — a combination that lets code run and then masquerade as trusted software. The cadence continued after this report, with 63 fixes including two zero-days in September 2022 and 77 fixes with three actively exploited zero-days by February 2023.

First-order effects

  • Windows and IE users who have not applied this update remain exposed to drive-by compromise — visiting a malicious site is enough for attackers to execute code, no user interaction required.
  • Organizations relying on Windows Authenticode-style signature checks lose that trust signal until patched, since the signature-spoofing zero-day lets malware appear legitimately signed.

Second-order effects

  • Security teams face another forced emergency patch cycle, adding to a backlog already shaped by prior exploited-zero-day months like August 2021's 44-fix release with three zero-days.
  • Attackers who built exploits around signature validation as a defense now have a working bypass template, raising the value of behavioral detection over static trust checks.

Third-order effects

  • If the pattern holds — exploited IE and Windows zero-days appearing across 2015, 2018, 2020, 2021, 2022, and 2023 — monthly patching becomes a permanent operational tax rather than a best practice, and browser engines tied to the OS become standing attack surface that outlives their active development.

The trend: Microsoft's Patch Tuesday has settled into a recurring arms race where actively exploited Windows and IE zero-days arrive faster than the platform can retire its legacy attack surface.

Discussion

  • Citrix Blogs Fermin J. Serna on x
    Citrix provides security update on Citrix Endpoint Management
  • @briankrebs @briankrebs on x
    Microsoft today released updates to plug at least 120 security holes in its Windows operating systems and supported software, including two newly discovered vulnerabilities that are actively being exploited. Back up and patch up, dear Windows (ab)users! https://krebsonsecurity.co…
  • @campuscodi Catalin Cimpanu on x
    Second zero-day is CVE-2020-1464, a file spoofing vulnerability in the Windows OS itself. “An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.” 👀👀👀👀 👀👀👀👀 👀 https://portal.msrc.microsoft.com/ ... https://twitte…
  • @campuscodi Catalin Cimpanu on x
    The Microsoft August 2020 Patch Tuesday updates are out. This month we have: -fixes for 120 vulnerabilities -17 rated “Critical” -fixes for two zero-days https://www.zdnet.com/... https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    First zero-day is CVE-2020-1380, an RCE in the Internet Explorer scripting engine https://portal.msrc.microsoft.com/ ... https://twitter.com/...