Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Microsoft Fixes Browser Flaw, Even in Windows XP

The move comes after governments around the world had advised consumers to use other browsers.

Ken Wolter/Shutterstock

Software giant Microsoft has released a fix to a critical vulnerability that hit its Internet Explorer Web browser over the weekend, and it has even fixed the flaw in versions for Windows XP, for which official support recently ended.

Microsoft announced the move in a company blog post earlier today. “This means that when we saw the first reports about this vulnerability, we said fix it, fix it fast, and fix it for all our customers. So we did,” Microsoft’s Adrienne Hall wrote.

Dustin Childs, a Microsoft security manager, wrote in a separate post that the company had seen only “limited targeted attacks” exploiting the vulnerability, but customers are advised to update their software as fast as they can, though most will see it updated by default.

Separately the security company FireEye said it had seen an increase in attacks using the vulnerability, which it has dubbed “Operation Clandestine Fox.” Initially it had spotted attacks only on versions 9, 10, and 11 of Internet Explorer running on Windows 7 and 8. That changed, it said, to include Windows XP and IE version 8.

FireEye added that the attacks have spread to new targets: “We have also observed that multiple, new threat actors are now using the exploit in attacks and have expanded the industries they are targeting. In addition to previously observed attacks against the Defense and Financial sectors, organizations in the Government and Energy sectors are now also facing attack.”

Disclosed in an unusual Saturday alert from Microsoft, the vulnerability by one estimate affected more than 56 percent of the world’s Web browsers currently in use. It’s a remote code execution vulnerability, which means an attacker can make a target computer run software after a successful attack. “The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer,” Microsoft’s alert said.

The pressure on Microsoft to fix the bug — even in Windows XP, a 13-year-old OS which it recently stopped officially supporting — was high as government computer security agencies in the U.S., the U.K. and Germany had advised against using IE until the flaw was patched.

This article originally appeared on Recode.net.

More in Technology

Podcasts
Are humanoid robots all hype?Are humanoid robots all hype?
Podcast
Podcasts

AI is making them better — but they’re not going to be doing your chores anytime soon.

By Avishay Artsy and Sean Rameswaram
Future Perfect
The old tech that could help stop the next airborne pandemicThe old tech that could help stop the next airborne pandemic
Future Perfect

Glycol vapors, explained.

By Shayna Korol
Future Perfect
Elon Musk could lose his case against OpenAI — and still get what he wantsElon Musk could lose his case against OpenAI — and still get what he wants
Future Perfect

It’s not about who wins. It’s about the dirty laundry you air along the way.

By Sara Herschander
Life
Why banning kids from AI isn’t the answerWhy banning kids from AI isn’t the answer
Life

What kids really need in the age of artificial intelligence.

By Anna North
Culture
Anthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque messAnthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque mess
Culture

“Your AI monster ate all our work. Now you’re trying to pay us off with this piece of garbage that doesn’t work.”

By Constance Grady
Future Perfect
Some deaf children are hearing again because of a new gene therapySome deaf children are hearing again because of a new gene therapy
Future Perfect

A medical field that almost died is quietly fixing one disease at a time.

By Bryan Walsh