Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Microsoft Fixes Browser Flaw, Even in Windows XP

The move comes after governments around the world had advised consumers to use other browsers.

Ken Wolter/Shutterstock

Software giant Microsoft has released a fix to a critical vulnerability that hit its Internet Explorer Web browser over the weekend, and it has even fixed the flaw in versions for Windows XP, for which official support recently ended.

Microsoft announced the move in a company blog post earlier today. “This means that when we saw the first reports about this vulnerability, we said fix it, fix it fast, and fix it for all our customers. So we did,” Microsoft’s Adrienne Hall wrote.

Dustin Childs, a Microsoft security manager, wrote in a separate post that the company had seen only “limited targeted attacks” exploiting the vulnerability, but customers are advised to update their software as fast as they can, though most will see it updated by default.

Separately the security company FireEye said it had seen an increase in attacks using the vulnerability, which it has dubbed “Operation Clandestine Fox.” Initially it had spotted attacks only on versions 9, 10, and 11 of Internet Explorer running on Windows 7 and 8. That changed, it said, to include Windows XP and IE version 8.

FireEye added that the attacks have spread to new targets: “We have also observed that multiple, new threat actors are now using the exploit in attacks and have expanded the industries they are targeting. In addition to previously observed attacks against the Defense and Financial sectors, organizations in the Government and Energy sectors are now also facing attack.”

Disclosed in an unusual Saturday alert from Microsoft, the vulnerability by one estimate affected more than 56 percent of the world’s Web browsers currently in use. It’s a remote code execution vulnerability, which means an attacker can make a target computer run software after a successful attack. “The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer,” Microsoft’s alert said.

The pressure on Microsoft to fix the bug — even in Windows XP, a 13-year-old OS which it recently stopped officially supporting — was high as government computer security agencies in the U.S., the U.K. and Germany had advised against using IE until the flaw was patched.

This article originally appeared on Recode.net.

More in Technology

Politics
The Supreme Court will decide when the police can use your phone to track youThe Supreme Court will decide when the police can use your phone to track you
Politics

Chatrie v. United States asks what limits the Constitution places on the surveillance state in an age of cellphones.

By Ian Millhiser
Future Perfect
The simple question that could change your careerThe simple question that could change your career
Future Perfect

Making a difference in the world doesn’t require changing your job.

By Bryan Walsh
Technology
The case for AI realismThe case for AI realism
Technology

AI isn’t going to be the end of the world — no matter what this documentary sometimes argues.

By Shayna Korol
Politics
OpenAI’s oddly socialist, wildly hypocritical new economic agendaOpenAI’s oddly socialist, wildly hypocritical new economic agenda
Politics

The AI company released a set of highly progressive policy ideas. There’s just one small problem.

By Eric Levitz
Future Perfect
Human bodies aren’t ready to travel to Mars. Space medicine can help.Human bodies aren’t ready to travel to Mars. Space medicine can help.
Future Perfect

Protecting astronauts in space — and maybe even Mars — will help transform health on Earth.

By Shayna Korol
Podcasts
The importance of space toilets, explainedThe importance of space toilets, explained
Podcast
Podcasts

Houston, we have a plumbing problem.

By Peter Balonon-Rosen and Sean Rameswaram