Microsoft fixes 17 critical and two zero-day flaws, including an actively-exploited RCE flaw in IE that can compromise PCs when users visit malicious sites
Microsoft says attackers have used a Windows zero-day to spoof file signatures and another RCE in the Internet Explorer scripting engine to execute code on users' devices.
Context & Ripple Effects
This Patch Tuesday is one entry in a long-running Microsoft ritual: the related coverage shows critical Internet Explorer remote code execution flaws going back to at least October 2015's Patch Tuesday, and an actively abused IE engine zero-day resurfacing in September 2021, where it was chained into attacks on Office applications.
What distinguishes this month is the pairing: alongside the exploited IE scripting-engine RCE that needs only a malicious website visit, attackers were also using a Windows zero-day to spoof file signatures — a combination that lets code run and then masquerade as trusted software. The cadence continued after this report, with 63 fixes including two zero-days in September 2022 and 77 fixes with three actively exploited zero-days by February 2023.
First-order effects
- Windows and IE users who have not applied this update remain exposed to drive-by compromise — visiting a malicious site is enough for attackers to execute code, no user interaction required.
- Organizations relying on Windows Authenticode-style signature checks lose that trust signal until patched, since the signature-spoofing zero-day lets malware appear legitimately signed.
Second-order effects
- Security teams face another forced emergency patch cycle, adding to a backlog already shaped by prior exploited-zero-day months like August 2021's 44-fix release with three zero-days.
- Attackers who built exploits around signature validation as a defense now have a working bypass template, raising the value of behavioral detection over static trust checks.
Third-order effects
- If the pattern holds — exploited IE and Windows zero-days appearing across 2015, 2018, 2020, 2021, 2022, and 2023 — monthly patching becomes a permanent operational tax rather than a best practice, and browser engines tied to the OS become standing attack surface that outlives their active development.
The trend: Microsoft's Patch Tuesday has settled into a recurring arms race where actively exploited Windows and IE zero-days arrive faster than the platform can retire its legacy attack surface.