• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.
  • The forums have been upgraded with support for dark mode. By default it will follow the setting on your system/browser. You may override it by scrolling to the end of the page and clicking the gears icon.

Microsoft Acts on MSIE RCE Vulnerability, Issues Hotfix

btarunr

Editor & Senior Moderator
Staff member
Joined
Oct 9, 2007
Messages
47,814 (7.40/day)
Location
Dublin, Ireland
System Name RBMK-1000
Processor AMD Ryzen 7 5700G
Motherboard Gigabyte B550 AORUS Elite V2
Cooling DeepCool Gammax L240 V2
Memory 2x 16GB DDR4-3200
Video Card(s) Galax RTX 4070 Ti EX
Storage Samsung 990 1TB
Display(s) BenQ 1440p 60 Hz 27-inch
Case Corsair Carbide 100R
Audio Device(s) ASUS SupremeFX S1220A
Power Supply Cooler Master MWE Gold 650W
Mouse ASUS ROG Strix Impact
Keyboard Gamdias Hermes E2
Software Windows 11 Pro
A major security remote code execution (RCE) vulnerability discovered in the Microsoft Internet Explorer set data security agencies on high alert. Microsoft noted that 1 in every 500 internet users were exposed to the vulnerability through unsafe websites. The exploit allows hackers to remotely execute code over an IE session to gain access to, and comprimise a machine.

In a security advisory updated today, Microsoft claims to have acted on the vulnerability by issuing a critical security update MS08-078 that went online at 1:00 PM, EST. The hotfix is available for all current versions of the web browser through Microsoft Update.

View at TechPowerUp Main Site
 
Wow.
Would this be a good suggestion to do since I don't even use IE?
 
What exactly does 1:500 mean? That's a horrible statistic because it has a lot of assumptions in it, and is a horrible "average" of users and uses.

For example, it could be that only 1:10 use credit cards on their PC. Does that mean:
  • For those that use CC, the risk is 1:50?
  • And for those that dont, the risk is zero?
(Just an example)

Earlier today it warning was for IE7. It seems that it is for all IE, since my update is now offering the following:

Capture014.jpg


It's unusual there is no much noise about a security update. It must be serious.

EVERYONE do the update!
 
What was meant was, 1 in every 500 got pwned (exposed to malware/hackers) due to that already.
 
This really is a fast fix, I only read about it on Yahoo's homepage yesterday. Got it installed on both rigs now.

Thanks have been added bta!
 
Hmm, better update then. I wouldn't use IE at all, but my stupid bank doesn't work with firefox.
 
I was hearing from my teacher that some major corporations have shut down their internet till everyone installs the hotfix. Pretty serious if you ask me. I assured him it would be ok, and made sure the computers I was working at had the fix, but still, pretty serious.
 
Wow.
Would this be a good suggestion to do since I don't even use IE?

It is a critical Fix, get it because even tho you dont use IE, you still do when you get Windows Updates, and also this exploit could expand beyond IE and make your Machine susceptible to domination
 
I still remember buying my 1st modem, it was a 2.4Kb swann crap but got me online. In a day and age where monochrome ruled the Earth, a friend foresore Internet banking become popular and usefull. It was that day i decided to never Internet Bank, never have since, and never will.

Im not saying that anyone that Internet Banks deserves to have all their assets relocated to some foreign country and used for prostitution, i dont know what im saying . . . I think im saying, DONT INTERNET BANK.

As for the unsafe websites, who said you should click on it . . . . Almost all of my clients admit to having gone to an unsafe website where they obtained a bug or two. They all knew it was unsafe, they all subconciously knew they would be harmed, yet they clicked. I try to educate my clients as much as i can. . . That one must guard him/herself and not await 3rd party software to do it for them.

The hotfix is more then welcomed. Educating the public is needed.
 
Last edited:
Windows Update on my server notified me of it. Installing now (hope it doesn't require restart)...
 
If you install via IE7 -> Microsoft Update or Windows Update website, you do. If you install via the integrated Windows Update client, you don't. I didn't have to restart the server but I had to restart my desktop. :(
 
I have vista service pack 2 beta on,do i still need the fix?
 
I just checked update and it was there so i have just done it.
 
What exactly does 1:500 mean? That's a horrible statistic because it has a lot of assumptions in it, and is a horrible "average" of users and uses.

For example, it could be that only 1:10 use credit cards on their PC. Does that mean:
  • For those that use CC, the risk is 1:50?
  • And for those that dont, the risk is zero?
(Just an example)

Earlier today it warning was for IE7. It seems that it is for all IE, since my update is now offering the following:

Capture014.jpg


It's unusual there is no much noise about a security update. It must be serious.

EVERYONE do the update!

o quite serious i actually was watching the news i think yesterday night and they had a whole thing on it.
 
Hopefully thats something windows automatic update would of sent havnt havnt any dramas with ie lately.
 
I've had no dramas except the usual with IE7 lately, although tbh I only use IE for checking e-mails.
 
Just got it now through auto update.
 
I say Ha-Ha if they found ... an other B!G security hole :nutkick:
I dont use InternetSuxxplorer (and I never did)
Opera - Firefox - Chrome This 3 browsers are much better than all Trident based crap
 
Well for some reason, windows update just popped up and it had the IE7 update. Now when I Installed and restarted for some reason my computer was not laggy anymore, and it was faster than it was.
 
Yeah i noticed the same thing go figure :p
 
The obnoxious windows update appeared during my download session overnight, thankyou very much MS for updating your crapware and inconveniencing me.
 
Back
Top