dcn-as logo
Story image

Zero-day Internet Explorer vulnerability exploited in the wild

25 Sep 2019

On September 23, Microsoft released an out-of-band patch for a zero-day vulnerability in Internet Explorer that has been exploited in the wild.

Exploiting the vulnerability gives an attacker the same privileges as the current user.

Tenable senior security response manager Satnam Narang shares his findings on the vulnerability.

Analysis

CVE-2019-1367 is a memory corruption vulnerability in Internet Explorer’s scripting engine in the way that objects in memory are handled.  

Exploitation of this vulnerability could result in the attacker gaining arbitrary code execution under the same privileges as the current user.

In the event that the current user has administrative privileges, an attacker could perform various actions on the system, from creating a new account with full privileges to installing programs or even modifying data.

To exploit the vulnerability, an attacker would have to host the exploit on a malicious website and socially engineer a user into opening that website in Internet Explorer.

In the case of a targeted attack, an attacker could include a link to the malicious website in an email or in a malicious email attachment (HTML file, PDF file, Microsoft Office document) that supports embedding the scripting engine content.

The vulnerability was discovered by Clément Lecigne of Google’s Threat Analysis Group (TAG).

Earlier this year, Lecigne discovered and reported two zero-day vulnerabilities: a use-after-free vulnerability in Google Chrome (CVE-2019-5786) and an elevation of privilege vulnerability in Microsoft Windows (CVE-2019-0808) that were exploited together in the wild.

Additional details about the in-the-wild exploitation of this vulnerability have not yet been made public by Lecigne and Google’s TAG, though we anticipate such details will be disclosed in a blog post in the near future.

Solution

Microsoft released an out-of-band patch for this vulnerability due to the report that it has been exploited in the wild.

Please refer to the Security Updates section for additional information on the IE Cumulative Update or relevant Security Updates.

Additionally, Microsoft has provided workarounds for both 32-bit and 64-bit systems by restricting access to the JScript.dll file.

An administrator can do so by entering specific commands into the command prompt; the commands are available at the end of the Microsoft security advisory page.

However, these workarounds should only be used as a temporary measure until patching is feasible.

Commands to revert the workarounds are also available on the Microsoft security advisory page.

ESET cybersecurity specialist Jake Moore says, “The importance of patching has never been so important and not just for those ‘early adopters’.

“Luckily there is a minimal share of the public still using IE as a browser, but it’s worth noting this could still have damaging consequences.”

Trustwave SpiderLabs EMEA director Ed Williams says, “The release of this patch underlines the importance of regular patching on an environment.

“It also highlights the importance of regular asset identification and vulnerability scanning of environments, for example, knowing what to patch once a vulnerability has been identified.

“We know that attackers are flexible and dynamic and will be looking to further leverage this vulnerability to suit their needs, be it financial or otherwise.

“While Internet Explorer isn’t as popular as it once was, it is still a rich target for attackers, and with the release of this patch, further emphasises why it is a business risk when compared to other browsers.

Story image
VMware adds cloud-native support to 5G telco cloud portfolio
The 5G-ready Telco Cloud Platform supports cloud-native technology and delivers applications and services across multi-cloud infrastructure.More
Story image
Pure Storage acquires Portworx for $370m, extends Kubernetes services and support
Pure Storage has signed an agreement to acquire Portworx for approximately $370 million in cash, with the aim of extending Kubernetes and containers solutions and support. This deal represents Pure Storage’s largest acquisition to date. More
Story image
Cambium Networks' "breakthrough" in 60 GHz fixed wireless broadband
The technology can deliver ‘fibre-like’ internet speeds at a lower cost and faster time to market than last-mile wired networks.More
Story image
From 1G to 5G: How innovations in cellular have shaped our lives
As we look to the present decade from 2020 onwards, 5G will be at the forefront. The race for 5G is not about merely deploying new infrastructure, but getting the first-mover advantage in who can build and take the leadership role in the host of new applications and services that 5G will enable.More
Story image
neutrality.one selects datamena for EMEA & Asia PoP
Cloud networking company neutrality.one is pushing further into the Asia, Middle East, and Africa regions with a new point of presence (PoP) in datamena’s Dubai facility.More
Story image
Blue Wireless expands 5G portfolio into the Americas
Before today’s announcement, the company had previously only expanded in the Europe and Asia Pacific regions; now, Blue Wireless has added the United States, Canada and Mexico to the list of countries it serves, bringing the total to 61.More