We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Zero-day vulnerability in Internet Explorer

Applies to Windows XP, IE6, IE7 and IE8

Deregistering the vulnerable DLL file worked fine.

http://news.softpedia.com/news/First-Post-Death-Windows-XP-Vulnerability-Already-Found-439562.shtml
«1

Comments

  • OnAndUp
    OnAndUp Posts: 981 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    Thanks :)

    Do they mean this is only an issue if you use IE - I don't. Or still a problem if you have it installed so best to do the mentioned fix?
    "Things can only get better.................c/o D:Ream #The 90's :D"
  • colin79666
    colin79666 Posts: 1,359 Forumite
    Part of the Furniture 1,000 Posts
    edited 28 April 2014 at 6:21PM
    Only an issue if you use IE. However many people still have it as their default browser, even if using another browser for day to day activity. This means that clicking a link in say a phishing email would launch IE and the machine gets pwned. No harm really in unregistering the DLL, practically no website legitimately uses VML.

    Some sane advice here: http://steve.grc.com/2014/04/28/a-quick-mitigation-for-internet-explorers-new-0-day-vulnerability/
  • joe134
    joe134 Posts: 3,336 Forumite
    edited 29 April 2014 at 7:11AM
    colin79666 wrote: »
    Only an issue if you use IE. However many people still have it as their default browser, even if using another browser for day to day activity. This means that clicking a link in say a phishing email would launch IE and the machine gets pwned. No harm really in unregistering the DLL, practically no website legitimately uses VML.

    Some sane advice here: http://steve.grc.com/2014/04/28/a-quick-mitigation-for-internet-explorers-new-0-day-vulnerability/
    Hi, as versions 10 and 11 are not affected by this,which I have installed, why not instal these, if you like IE.
    I use AOL browser, purely as it's my ISP,simple, and e-mails are easier,BUT, it piggy backs IE, which, I dislike to use.I know it's disliked on here, clogs the system, but I fing it as quick as Chrome, or Firefox personal choice
    Use Chrome too,
  • giraffe69
    giraffe69 Posts: 3,634 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    Hi, as versions 10 and 11 are not affected by this,which I have installed, why not instal these, if you like IE.

    If you are still using XP the IE10 and 11 won't work. IE8 is the last version that was supported (no more, of course)
  • Oblivion
    Oblivion Posts: 20,248 Forumite
    Part of the Furniture 10,000 Posts Photogenic
    It seems that Microsoft have put their hands up to another flaw affecting IE 6 to 11 now!


    http://www.bbc.co.uk/news/technology-27184188
    ... Dave
    Happily retired and enjoying my 14th year of leisure
    I am cleverly disguised as a responsible adult.
    Bring me sunshine in your smile
  • grumpycrab
    grumpycrab Posts: 5,042 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Bake Off Boss!
    Oblivion wrote: »
    It seems that Microsoft have put their hands up to another flaw affecting IE 6 to 11 now!


    http://www.bbc.co.uk/news/technology-27184188
    Same thing. The later versions of IE are already fixed.
  • Oblivion
    Oblivion Posts: 20,248 Forumite
    Part of the Furniture 10,000 Posts Photogenic
    edited 29 April 2014 at 10:25AM
    grumpycrab wrote: »
    Same thing. The later versions of IE are already fixed.


    Are you sure? The Microsoft advisory was only published on 26th April. I've just checked and there haven't been any updates issued since then.


    https://technet.microsoft.com/en-US/library/security/2963983
    ... Dave
    Happily retired and enjoying my 14th year of leisure
    I am cleverly disguised as a responsible adult.
    Bring me sunshine in your smile
  • grumpycrab
    grumpycrab Posts: 5,042 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Bake Off Boss!
    I think its the same one (VGX.dll). IE 10 and 11 were already protected (at least under Windows 8 and 8.1).
  • joe134
    joe134 Posts: 3,336 Forumite
    giraffe69 wrote: »
    If you are still using XP the IE10 and 11 won't work. IE8 is the last version that was supported (no more, of course)
    Hi G, I use windows 7, and IE 10, and still cannot fathom out if these are affected, reading the last 2 posts.
    Very vague.
  • OneADay
    OneADay Posts: 9,031 Forumite
    1,000 Posts Combo Breaker
    joe134 wrote: »
    Hi G, I use windows 7, and IE 10, and still cannot fathom out if these are affected, reading the last 2 posts.
    Very vague.

    It affects all versions of Windows I think - except those running in restricted mode, Windows Server 2008 etc.

    Disabling flash plugin is the fix for now. If you have XP, well use a different browser.

    http://www.informationweek.com/software/operating-systems/microsoft-no-ie-patch-for-windows-xp/d/d-id/1234903
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.1K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 602.9K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.