Showing posts with label IE10. Show all posts
Showing posts with label IE10. Show all posts

Wednesday, December 19, 2018

Out-of-Band Security Update for Internet Explorer



Microsoft released an out-of-band security update for Internet Explorer 11 on Windows 10, Internet Explorer 11 on Windows 8.1 Update, Internet Explorer 11 on Windows 7 SP1, Internet Explorer 10 on Windows Server 2012, Internet Explorer 9, Windows Embedded Standard 2009 and Windows Embedded POSReady 2009.

The update addresses  remote code execution vulnerability CVE-2018-8653 that exists in the way that the scripting engine handles objects in memory in Internet Explorer.

It is strongly advised that this update be installed as soon as possible. (Note: For Windows RT and Windows RT 8.1, this update is available through Microsoft Update only.)

 
More:  For more information about the updates released today, see https://portal.msrc.microsoft.com/en-us/security-guidance/summary.  Updates can be sorted by OS from the search box. Information about the update for Windows 10 is available at Windows 10 Update history.



References


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...





Monday, November 10, 2014

Updates to Internet Explorer ActiveX Blocking

Internet Explorer 11


Blocking of out-of-date ActiveX controls was added to Internet Explorer versions 9 through 11 in October.  
With the update being released in November (11NOV2014), Microsoft is adding additional changes to out-of-date AxtiveX control blocking. 

To be included will be updates to currently supported operating system and browser combinations.  This is a welcome addition for users of Windows Vista.  Another addition to ActiveX blocking will include blocking out-of-date Silverlight.

Note:  After January 12, 2016, only the following configurations will be supported:


Windows operating system Internet Explorer version
Windows Vista SP2 Internet Explorer 9
Windows Server 2008 SP2 Internet Explorer 9
Windows 7 SP1 Internet Explorer 11
Windows Server 2008 R2 SP1 Internet Explorer 11
Windows 8.1 Internet Explorer 11
Windows Server 2012 Internet Explorer 10
Windows Server 2012 R2 Internet Explorer 11


References:

Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Thursday, May 01, 2014

Out of Band Security Update for IE Zero-Day Vulnerability


Microsoft released an out-of-band security update to address the security vulnerability in Internet Explorer described in Microsoft  Security Advisory 2963983.

Of important note:  Although Windows XP is no longer supported by Microsoft, the decision was made to issue a security update for Windows XP users.

Critical:

  • MS14-021 -- Security Update for Internet Explorer (2965111) 

    This security update resolves a publicly disclosed vulnerability in Internet Explorer. The vulnerability could allow remote code execution if a user views a specially crafted webpage using an affected version of Internet Explorer. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


    References




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...




    Sunday, April 27, 2014

    Security Advisory 2963983, IE Zero-Day Vulnerability

    Security Advisory
    Microsoft released Security Advisory 2963983 which relates to a vulnerability in Internet Explorer.

    With the vulnerability, an attacker could cause remote code execution if someone visited a malicious website with an affected browser. Generally, this would occur by an attacker convincing someone to click a link in an email or instant message.

    Although the vulnerability affects all versions of IE, at this time, Microsoft is aware of limited, targeted attacks, in which the exploit observed appears to target IE9, IE10 and IE11.


    Additional details about the exploit are available from the FireEye Blog, New Zero-Day Exploit targeting Internet Explorer Versions 9 through 11 Identified in Targeted Attacks.

    Recommendations 

    As illustrated in the "Security Research and Defense Blog" reference below, users of IE 10 and 11 should ensure they haven't disabled Enhanced Protection Mode. 

    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET).  The recommended setting for EMET 4.1, available from KB Article 2458544, is automatically configured to help protect Internet Explorer. No additional steps are required.

    See the Tech Net Advisory for instructions on changing the following settings to help protect against exploitation of this vulnerability:
    • Change your settings for the Internet security zone to high to block ActiveX controls and Active Scripting
    • Change your settings to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone. 

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Wednesday, February 19, 2014

    Microsoft Security Advisory 2934088

    Security Advisory
    Microsoft released Security Advisory 2934088 which impacts Internet Explorer 9 and 10. Internet Explorer 6, 7, 8 and 11 are not affected.

    Although Internet Explorer 9 is vulnerable, at this time, Microsoft is only aware of limited, targeted attacks against Internet Explorer 10. This issue allows remote code execution if users browse to a malicious website with an affected browser. This would typically occur by an attacker convincing someone to click a link in an email or instant message.

    Recommendations

    Users of Internet Explorer 10 should update to IE11, available here.

    If you use Internet Explorer 9 or 10 and are unable to update to Internet Explorer 11, it the below-linked Fix it solution is strongly advised.
     
    Enable Fix itDisable Fix it


    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory as well as the Security Research and Defense Blog article.

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Tuesday, September 17, 2013

    Security Advisory 2887505 and Microsoft Fix it

    Security Advisory
    Microsoft released Security Advisory 2887505 which relates to an issue with Internet Explorer.

    It is important to note that there are a limited number of targeted attacks which are specifically directed at Internet Explorer 8 and 9. The issue, however, could potentially affect all supported versions of IE.

    As described by Dustin Childs in the below-referenced MSRC Blog post,
    "This issue could allow remote code execution if an affected system browses to a website containing malicious content directed towards the specific browser type. This would typically occur when an attacker compromises the security of trusted websites regularly frequented, or convinces someone to click on a link in an email or instant message."

    Mitigations

    Microsoft has made available a Fix it solution for users of Internet Explorer.  Additional mitigations include the following advice, also from the MSRC Blog post:

    • Set Internet and local intranet security zone settings to "High" to block ActiveX Controls and Active Scripting in these zones
      This will help prevent exploitation but may affect usability; therefore, trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.
    • Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and local intranet security zones
      This will help prevent exploitation but can affect usability, so trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.
    Below are the links to both apply and uninstall the Fix it solution.  Note:  The Fix it solution applies only 32-bit versions of Internet Explorer.
     
    Apply Fix itUninstall Fix it


    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory.

    If you have Windows Vista or Windows 7 installed, you should have updated to IE9 or IE10.  In the event you haven't, it is strongly advised that you update!

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Sunday, June 16, 2013

    Microsoft Fix it to Disable Java in Internet Explorer

    java

    Java, how we love to hate you!  Many people have uninstalled Java and do not miss it.  That is most likely because they do not have desktop applications that require Java. Unfortunately, that is not the situation for those people who use Java-dependent software programs. 

    Until recently, Internet Explorer was the only major browser that did not provide a way to disable Java.  The only way to completely disable Java in IE was to disable Java through the Java Control Panel, which meant re-enabling Java when using Java-dependent programs.  That is no longer true!

    Microsoft released a Microsoft Fix it solution designed to block all Java web-attack vectors through Internet Explorer.  As explained by Cristian Craioveanu in the below-linked Security Research & Defense Blog article, the Fix it solution is made up of two parts. 
    1. The Fix It uses the Windows Application Compatibility Toolkit to change the behavior of Internet Explorer at runtime to prevent Oracle’s Java Web plugins from loading.  As a result, the Java ActiveX dlls are not loaded.
    2. The second part of the Fix it clears the access control list (ACL) in the registry for the Java Network Loading Protocol (JNLP) handler which prevents Internet Explorer from automatically opening  files.  

    Instructions

    Before installing the Fix it solution, please follow the following suggestions:

    1.  Create a restore point

    2.  Back up the Registry
    3.  Apply the Fix it

    Disable the Java web-plugin

    Apply Fix it
    Restore the Java web-plugin
     
    Uninstall Fix it

    4.  Restart Internet Explorer
    For the changes to take effect, restart IE.

    To undo the changes, run Microsoft Fix it 50995 and restart IE.

    The Fix it solution has been tested by Microsoft and will work for all versions of Java from versions 5 and above.  It also works on all supported versions of Internet Explorer, whether 32- or 64-bit.


    References


    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Tuesday, February 26, 2013

    IE10 for Windows 7 Released

    IE10

    Internet Explorer 10 has been released globally for Windows 7.  It is available in 95 languages.

    Initially, the update will be available via Windows Update for those running the IE10 release preview, followed in stages for the remaining Windows 7 users.  If you would rather not wait to be offered the update, IE10 is available via the links shown below.

    Note that IE10 is not compatible with Windows Vista.

    Key Improvements

    Key improvements in IE9 include improved performance, security, and privacy.  Of major significance are the results of the independent testing conducted by NSS Labs, referenced below, in which IE10 with App Rep had a mean malware block rate of 99.1%.

    System Requirements

    Processor
    • Computer with a 1 gigahertz (GHz) 32-bit (x86) or 64-bit (x64) processor.
    Operating system
    • Windows 7 32-bit with Service Pack 1 (SP1) or higher
    • Windows 7 64-bit with Service Pack 1 (SP1) or higher
    • Windows Server 2008 R2 with Service Pack 1 (SP1) 64-bit
    Memory
    • Windows 7 32-bit—512 MB
    • Windows 7 64-bit—512 MB
    • Windows Server 2008 R2 64-bit—512 MB
    Hard drive space
    • Windows 7 32-bit—70 MB
    • Windows 7 64-bit—120 MB
    • Windows Server 2008 R2 64-bit—200 MB
    Display
    • Super VGA (800 x 600) or higher-resolution monitor with 256 colors 

    Download Link

    Go here to determine if your PC is running the 32-bit or 64-bit version of Windows.

    References




    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Monday, January 14, 2013

    MS13-008 Released for Security Advisory 2794220


    Microsoft released an out-of-band security update to address the issue described in  Security Advisory 2794220.

    The update is to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected.  

    This update is critical if you have Internet Explorer versions 6, 7 or 8 installed on your computer.  Windows XP users of IE6 or IE7 should update to IE8 as soon as possible.  Windows Vista and Windows 7 users should be using IE9.

    Note:  The Advance Notice for this update to Internet Explorer versions 6-8 indicated if the Microsoft Fix it was applied, it was not necessary to uninstall it prior to updating IE. 

    The advice provided now is to disable the Fix it after updating as it is no longer required.

    Fix it


    Disable

    Fix this problem
          Microsoft Fix it 50972

    References:



    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Sunday, January 13, 2013

    Advance Notification for Update to Address Security Advisory 2794220

    Security Bulletin
    On Monday, January 14, 2013, Microsoft is planning to release an out-of-band critical security update for the issue described in  Security Advisory 2794220.

    The update is to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected. 

    Although Microsoft has seen only a limited number of customers affected by the issue, the potential exists that more could be affected.  Thus, it is advised that the update be installed as soon as possible. 

    Even with the update, if your operating system is Windows Vista or Windows 7, update to Internet Explorer 9.  For Windows XP, your system will be more secure if you update to Internet Explorer 8.

    If you applied the Fix it released in Security Advisory 2794220, it will not need to be uninstalled before applying the security update.

    References



    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Saturday, December 29, 2012

    Microsoft Security Advisory 2794220

    Security Advisory
    Microsoft released Security Advisory 2794220 to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected.

    At this time, Microsoft is aware of a very small number of targeted attacks.  This issue allows remote code execution if users browse to a malicious website with an affected browser.  Generally, this is a result of an attacker convincing someone to click a link in an email or instant message.

    Recommendations:

    Microsoft is actively working to develop a security update to address the issue.  In the meantime, please consider the following suggestions:

    1.  Update Internet Explorer -- If your operating system is Windows Vista or Windows 7, update to Internet Explorer 9.  For Windows XP, your system will be more secure if you update to Internet Explorer 8.

    2.  Update or Uninstall Java -- Current exploits of this type of vulnerability in Internet Explorer use third-party software, including Oracle’s Java, to help obtain reliable exploitation.

    Most home computer users no longer need Java.  Following are reasons why someone may need Oracle Sun Java installed on their computer:

    • Playing on-line games generally requires Java.
    • With OpenOffice, Java is needed for the items listed here
    • It used to be that Java was needed for websites to be properly displayed. However, that is generally not the case now with Flash having taken over.
    • There may be commercial programs that depend on Java. If Java is needed for a software installed on your computer, there should be a prompt for it.
    If you need Java, be sure you have uninstalled all old, vulnerable versions and have only the most recent release installed on your computer.  The current version of Java is Version 7 Update 10.
     

    3.  Install and configure EMET -- The Enhanced Mitigation Experience Toolkit was designed to help prevent hackers from gaining access to your system. It prevents exploitation by applying in-box mitigations to help protect against this and other issues and should not affect usability of websites.

    An easy guide for EMET installation and configuration is available in KB2458544.  Additional information about configuring EMET is available in the EMET User's Guide, in the following locations:
    • 32-bit systems -- C:\Program Files\EMET\EMET User's Guide.pdf
    • 64-bit systems -- C:\Program Files (x86)\EMET\EMET User's Guide.pdf
    Additional suggestions are available in the MSRC Blog post and the Security Advisory, referenced below.

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Monday, October 08, 2012

    Critical Adobe Flash Player Update Released



    Adobe Flash Player was updated to address security vulnerabilities.  These updates address a vulnerability that could cause the application to crash and potentially allow an attacker to take control of the affected system.

    Note:  For users of Internet Explorer 10, Microsoft updated Security Advisory 2755801.  If you do not have Automatic Updates enabled, the Flash Player update can be downloaded from the Download Center at Update for Internet Explorer Flash Player for Windows 8 Release Preview (KB2758994).

    See the MSRC Blog post at Security Advisory 2755801 addresses Adobe Flash Player issues for additional information regarding Adobe Flash Player updates to IE10. 

    November 6, 2012 Update:  Security Advisory 2755801 revised to address Adobe Flash Player issues.

    Update Information

    The newest version for Windows and Macintosh is 11.4.402.287.  For Linux, the newest version is 11.2.202.243.

    Release date: October 8, 2012
    Vulnerability identifier: APSB12-22
    Priority:  Critical
    CVE numbers: CVE-2012-5248, CVE-2012-5249, CVE-2012-5250, CVE-2012-5251, CVE-2012-5252, CVE-2012-5253, CVE-2012-5254, CVE-2012-5255, CVE-2012-5256, CVE-2012-5257, CVE-2012-5258, CVE-2012-5259, CVE-2012-5260, CVE-2012-5261, CVE-2012-5262, CVE-2012-5263, CVE-2012-5264, CVE-2012-5265, CVE-2012-5266, CVE-2012-5267, CVE-2012-5268, CVE-2012-5269, CVE-2012-5270, CVE-2012-5271, CVE-2012-5272
    Platform: All Platforms

    Flash Player Update Instructions


    Flash Player for Windows, Macintosh, Linux and Solaris

    Although Adobe suggests downloading the update from the Adobe Flash Player Download Center or by using the auto-update mechanism within the product when prompted, if you prefer, direct download links are available.


    Notes:
    • Users of Adobe AIR 3.3.0.3670 for Windows and Macintosh should update to Adobe AIR 3.4.0.2710.
    • Beginning with Adobe Flash Version 11.3, the universal 32-bit installer will include the 32-bit and 64-bit versions of the Flash Player.  
    • If you use the Adobe Flash Player Download Center, be careful to uncheck the optional McAfee Security Plus box.  It is not needed for the Flash Player update.
    • Uncheck any toolbar offered with Adobe products if not wanted.
    • If you use alternate browsers, it is necessary to install the update for both Internet Explorer as well as the update for alternate browsers.
    • The separate 32-bit and 64-bit uninstallers have been replaced with a single uninstaller.
    Adobe Flash Player for Android

    The latest version for Adobe Flash Player for Android is available by downloading it from the Android Marketplace by browsing to it on a mobile phone.

    Verify Installation

    To verify the Adobe Flash Player version number installed on your computer, go to the About Flash Player page, or right-click on content running in Flash Player and select "About Adobe Flash Player" from the menu. 

    Do this for each browser installed on your computer.

    To verify the version of Adobe Flash Player for Android, go to Settings > Applications > Manage Applications > Adobe Flash Player x.x.

    References







    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Monday, March 05, 2012

    Windows 8 Consumer Preview: Getting Started

    The next version of the Microsoft operating system, Windows 8, has reached what is called "Consumer Preview".  Although defined by Microsoft as pre-release software, the Consumer Preview could also be referred to as a high end beta, with the next installment being RTM (Release to Manufacturing).

    Although Windows 8 Consumer Preview is a solid operating system, it is not advisable to install beta software on a production computer.  In other words, if you do not have a spare computer or a partition to dual-boot Windows 8, I strongly advise that you wait until after the final release, create a separate partition (see Create and format a hard disk partition) or test the operating system in a virtual machine.

    Rather than replicating the excellent documents already created by experienced and respected bloggers and web sites, I have collected a series of articles and tutorials that will guide your testing of Windows 8 Consumer Preview.

    System Requirements and Compatibility

    Although Microsoft has stated that Windows 8 Consumer Preview works on the same hardware that powers Windows 7, below are the recommended system requirements for running Windows 8 Consumer Preview.  

        Processor: 1 gigahertz (GHz) or faster
        RAM: 1 gigabyte (GB) (32-bit) or 2 GB (64-bit)
        Hard disk space: 16 GB (32-bit) or 20 GB (64-bit)
        Graphics card: Microsoft DirectX 9 graphics device or higher

    Additional requirements to use certain features:
    •   To use touch, a tablet or a monitor that supports multitouch is needed.
    •   To access the Windows Store and to download and run apps, you need an active Internet connection plus a screen resolution of at least 1024 x 768.
    •   To snap apps, you need a screen resolution of at least 1366 x 768.

    If you have a netbook or other computer running Windows 7 that isn't capable of a screen resolution at the levels indicated above, as illustrated by Barb Bowman in Windows 8 Consumer Preview Installed on Eee PC Netbook, you can still run Windows 8!  You may also want to read Paul Thurrott's articles, Some Thoughts About the Windows 8 System Recommendations and The Netbook Experience.

    For compatibility concerns, check the Windows 8 Consumer Preview Compatibility Center to find out whether your favorite applications and devices are compatible with Windows 8.  Links on the results page will direct to product Updates, Drivers, and Downloads.

    Installing Windows 8 Consumer Preview

    Now that you are ready to install Windows 8 Consumer Preview, it is time to select the best method for how you will be testing the operating system.

    Download

    Windows 8 Consumer Preview Setup:
    Windows 8 Consumer Preview Setup will check to see if your PC can run Windows 8 Consumer Preview and will select the right download. 
    Also included in Setup is a compatibility report and upgrade assistance. Built-in tools for creating an ISO or bootable flash drive are available for some previous versions of Windows (excluding Windows XP and earlier).

    Windows 8 Consumer Preview ISO formats:
    Windows 8 Consumer Preview ISO files (.iso) are provided as an alternative to using Windows 8 Consumer Preview Setup. ISO files are available for both 32-bit (2.5 GB) and 64-bit (3.3 GB). With the ISO files, use this Microsoft-provided Product Key: DNJXJ-7XBW8-2378T-X22TX-BKG7J

    Installation

    It seems that there is always more than one way to accomplish a task with Microsoft software.  That is the case with installing Windows 8 Customer Preview as well.  Unless you are very experienced, I recommend using the web installer to create a a bootable Windows 8 DVD using the .ISO file or bootable thumb drive or installing in a virtual machine.

    Navigating Windows 8

    Navigating Windows 8 will require an adjustment.  Take time to read about the new Metro style and learn about the new terminology, such as tiles and charms as well as touch terminology, including swipe and slide.

    For an overview, see Windows 8 Features and Terminology.  A more complete resource is The Windows 8 Glossary, used for creating translations.  Filtering by "locked" results in a set of definitions locked by Microsoft.

    Metro Style

    Metro Style is the name given to the Windows 8 user interface.  It is the new start screen, made up of tiles that represent applications, replacing the Start menu.  It is the first screen shown on start up.

    Metro is optimized for touchscreens as well as mice and keyboards.  Derick Campbell (Microsoft Research) has an excellent tutorial on navigating Windows 8.  Dude, Where’s My Windows 8 Start Menu? will go a long way to clearing up your confusion with Metro.

    After you have become more comfortable with Windows 8, you will want to locate more advanced functions, such as the control panel, task manager, device manager and other system management tools.  Ed Bott's article will help you locate Shortcuts and surprises in the Windows 8 Consumer Preview.

    Keyboard Shortcuts

    Whether you have a touch screen or use a keyboard or mouse, navigating Windows 8 will be a change from what you are accustomed to.  A comprehensive list of keyboard shortcuts is included in the ars technica article, Old dogs, get ready for new tricks: how to use the Windows 8 Consumer Preview.

    Derick Campbell created an online Word Document which includes a comprehensive list of keyboard shortcuts with the corresponding touch and mouse actions.  Consider downloading the file and annotating it with your own notes:  Win8 Shortcuts.

    Security

    Microsoft Security Essentials has been renamed Windows Defender for Windows 8.  Windows Defender is included in the install of Windows 8 Consumer Preview and enabled by default.  If you prefer to use a different antivirus solution, check the entries in the Compatibility Center.   You may find that your favorite program is not listed yet as compatible, yet, as in the case of ESET Smart Security, 15 out of 16 people reported it compatible with Windows 8.

    Problems

    There are times when things just do not go right.  In the case of Windows 8 Customer Preview, please keep in mind that Windows 8 Consumer Preview is pre-release software.

    Oops!

    What can you do if disaster strikes and your Windows 8 installation is totally messed up?


    Reset!
    Windows 8 has a new service that returns your PC to its factory clean state by wiping it out and reinstalling Windows.  Reset removes all personal data, apps, and settings and completes a fresh install of Windows 8.

    Refresh!
    With the Refresh option, you keep all personal data, Metro style apps, and important settings from the PC, as well as a clean copy of Windows 8.
    Reset and refresh are accessible through the "PC Settings" app.

    Help and Support


    Other Resources




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...