6 ms·
Internet Explorer zero-day
- Someone1234 8y agoThe irony is that Microsoft never supported NPAPI in Edge to improve security, and left NPAPI in IE11 indefinitely so any business (which is millions) stuck on NPAPI are left using IE11 for many years to come (Java Applets, Flash, ActiveX, etc). It is one of those decisions taken with the best possible motives, but that will have massive unintended consequences and keep IE11 on life-support well into the 2020s.
- yuhong 8y agoIt is not NPAPI. It has not been supported since IE 5.5 SP2.
- UnoriginalGuy 8y agoThey never said it was, they said that's why IE11 remains popular.
- kerng 8y ago>> Microsoft has released a patch for this vulnerability... Still, would be good to see IE go away.
- SimeVidas 8y agoIt is going away … slowly :-)
- falcolas 8y agoWhy? To reinforce the browser monoculture that is getting worse and worse? Competition is good, even if some of the options aren't perfect.
- LocalPCGuy 8y agoI make that argument myself fairly often, but IE should go away. Microsoft would prefer users use Edge, and are not updating IE except for security patches. So while I will join you in railing against people who say everyone should adopt [browser of choice here], I don't have a problem saying Microsoft IE needs to go away.
- butz 8y agoWell, there's Edge, that has decent standards support and timely updates. As for Internet Explorer - it's time for it to retire.
- kerng 8y agoMicrosoft has Edge, no need for IE besides backward compatibility for ActiveX and VBScript and such things that some enterprises might still depend on. It's actually amazing how long Microsoft supports things compared to others in the industry.
- baxtr 8y agoI don’t think the current title “internet explorer 0-day discovered” is correct. An new way to exploit the zero-day was discovered. But not bug itself. In late April, two security companies (Qihoo360 and Kaspersky) independently discovered a zero-day for Internet Explorer (CVE-2018-8174), which was used in targeted attacks for espionage purposes. This marks two years since a zero-day has been found (CVE-2016-0189 being the latest one) in the browser that won’t die, despite efforts from Microsoft to move on to the more modern Edge.
- jwilk 8y agoAs I understand it, it was a 0-day exploit when it was discovered in "late April". (That is, it was exploing a then-unknown bug.)
- kodablah 8y ago> despite efforts from Microsoft to move on to the more modern Edge. Then allow me to use Edge as a Windows control a la MSHTML in a non-UWP app. It's like if Chrome were suddenly made close source and non-embeddable and then Google complaining about insecure Electron apps.
- chrismorgan 8y agoYour analogy is imperfect; for MSHTML and EdgeHTML are first-party, while Electron is third-party; and it’s not just MSHTML that Microsoft are pushing people away from, but the entire Win32 API—Microsoft’s been saying, use WinRT instead, and you can have EdgeHTML there. Notably, Microsoft has been steadily stepping back from this vision in the last few years, and EdgeHTML is expected to be exposed to Win32 apps at some point (the impression I have is that it is expected sooner rather than later). It’s a nuisance that it isn’t already there, but it is coming. Note also that Chromium isn’t embeddable on its own; it’s only because it’s open source that anything has been able to embed it at all. It has no stable API, so CEF has to wrap it and shed some functionality to ensure it’ll keep working across more than just a few releases of Chromium, as changes are made therein. The Electron project basically builds itself inside Chromium instead, see https://electronjs.org/blog/electron-internals-building-chromium-as-a-library https://electronjs.org/blog/electron-internals-building-chro.... But really, IE has enough things needing it that removing it outright isn’t an option yet, and won’t be for quite a few years. I can imagine in a few years’ time not installing IE by default, and making the MSHTML widget actually be EdgeHTML instead if IE’s not installed, but even that I expect would break quite a bit of software. And Microsoft cares a lot about not breaking compatibility. It’ll be interesting to see what they do about it. (You may well know these points already, kodablah; I’m providing them as much for background for others reading as for you.)
- kodablah 8y agoSure the analogy is imperfect. I also don't have a perfect analogy for a browser vendor hobbling its newer product. But I'm just appealing to common sense wrt not addressing an extremely common use of something yet wanting that something to stop being used. I personally don't think they should implement the MSHTML/COM APIs with Edge any more than I think they should implement ActiveX on Edge. The old tech can die its slow death, so long as there is a viable replacement. Selfishly, I want this for https://github.com/zserge/webview https://github.com/zserge/webview to watch Electron adoption decrease or even an API-compat version using shared libs already on the system.
- gcb0 8y agoany way sites that host user generated content can mitigate this?
- Froyoh 8y agoObligatory "who still uses IE?"
- chrismorgan 8y agoEnough people, especially in businesses, that removing it would be catastrophic for Microsoft.
- meuk 8y agoI know several companies who developed internal applications using Silverlight. They still have to use Internet Explorer.
- rasz 8y agoanswer is right there in the article: Operating System
- Sylos 8y agoThe least number of them use it voluntarily. It's usually in bigger corporations where it's set as default browser and even if you have an option of installing a different browser, there's no way of getting into the intranet with that.
- astura 8y agoDoesnt matter, this exploit was actually being deployed through a word document, which bypassed the need to actually use IE to be vulnerable.
- fencepost 8y agoAnyone who still hasn't migrated off Windows 7 or (for whatever reason) 8.1.
- TelAvivHacker 8y agoIsn’t this an old browser? What about Edge?
- mtgx 8y agoMany of the worst Edge bugs are actually due to some backwards compatibility with IE.
- Jerry2 8y agoA much better analysis and the source of the article is here: https://securelist.com/root-cause-analysis-of-cve-2018-8174/85486/ https://securelist.com/root-cause-analysis-of-cve-2018-8174/...
- jacksmith21006 8y agoDoes anyone still use ie?
- blueline 8y agoyes
- Yuioup 8y agoUnfortunately, yes.
- Zelphyr 8y agoVery much so. I've worked with major corporations that are still standardized on IE9. Meaning, every employee's computer has IE9 on it. IE6 is still used by a lot of companies simply because they have too much ActiveX code they don't want to migrate.
- fencepost 8y agoI know of hospitals that a few years back were requiring IE 6 for their physician portal - long after that version was EOL. I think some are still using those older versions, but now they're doing it the safe way - running it as a remote application connected to via Citrix and hosted on a dedicated system. It's still jarring to see an old IE version icon on a task bar though.
- sbov 8y agoIn 2016, we shutdown one of our websites where around 11% of our userbase was still on IE6.
- sus_007 8y agoOne can also simply disable IE by going through Windows' Turn On/Off Windows Features menu. I wonder why do they not do it by default if they want their users to use Edge ahead of any alternatives.
- copperx 8y agoFor most "why does Windows xxx?", the answer is Enterprise. I bet there are many IE-only Intranet websites in the Enterprise world.
- sanlyx 8y agoBecause third-party software, specially old third party software, still uses mshtml and disabling Internet Explorer also gets rid of mshtml IIRC
- Zelphyr 8y agoAfter over twenty years of the abomination that is browsers produced by Microsoft, I'm ready to beg them to stop making a browser. EVERY. SINGLE. TIME. they release a new version or new name of their browser, they say, "But this time its going to blow the other guys out of the water in terms of speed, security, and standards compliance!" And EVERY. SINGLE. TIME. they drop the ball in significant ways.
- JeremyBanks 8y agoEdge is one of the best browsers, as promised, and this didn’t happen in Edge.