Krebs on Security

In-depth security news and investigation

Brian Krebs

  • About the Author
  • Blog Advertising
  • 14
    Jan 13

    Microsoft Issues Fix for Zero-Day IE Flaw

    Microsoft today deviated from its usual monthly patch cycle in issuing an emergency security update to fix a critical security hole in its Internet Explorer Web browser that attackers have been exploiting to break into Windows PCs.

    IEwarningThe update, MS13-008, addresses a single vulnerability in IE versions 6 through 8, and is available through Windows Update. The patch comes a little more than two weeks after security firms began seeing evidence that hackers were leveraging the vulnerability in targeted attacks. Microsoft maintains that it has seen only a limited number of attacks against the flaw, but acknowledged in a blog post that “the potential exists that more customers could be affected.”

    Prior to today, Microsoft released a stopgap Fix It tool to help blunt attacks against the IE flaw. According to Microsoft, “if you previously applied the Fix it offered through the advisory, you do not need to uninstall it before applying the security update released today. However, the Fix it is no longer needed after the security update is installed, so we are recommending that you uninstall it after you have applied the update to your system.” Users who applied the Fix It solution can uninstall it by clicking the Fix It icon under the words “Disable MSHTML shim workaround” at this page.

    Related Posts:
    • Microsoft: Hold Off Installing MS13-036
    • Critical Updates for Windows, Adobe Flash, Air
    • Fat Patch Tuesday
    • Patch for Critical Windows Flaw Available
    • Microsoft Fixes Zero-Day, Four Other Flaws in IE

    Tags: CVE-2012-4792, Fix it, FixIt, IE 0day, IE zero day, internet explorer, microsoft, MS13-008

    This entry was posted on Monday, January 14th, 2013 at 2:08 pm and is filed under Time to Patch. You can follow any comments to this entry through the RSS 2.0 feed. Both comments and pings are currently closed.

    5 comments

    1. JimV
      January 14, 2013 at 3:08 pm

      If you previously applied the FixIt workaround to temporarily gain protection from this exploit and will now need to remove it per the MS advisory, that FixIt tool isn’t immediately available from the link Brian provided but both can be accessed at the following:

      http://support.microsoft.com/kb/2799329

      • BrianKrebs
        January 14, 2013 at 3:42 pm

        Thanks, Jim. I meant to put that in earlier. Will update it with that link now.

    2. Debbie Kearns
      January 14, 2013 at 3:28 pm

      Thanks for the heads-up. I already installed the patch, so I’m all set! :)

    3. A
      January 16, 2013 at 3:45 am

      Windows Update refuses to tell me about this one for some reason.

      • A
        January 16, 2013 at 3:49 am

        Whoops, that’s because I have IE 9.