Skip to main content

Internet Explorer has a zero-day bug that Microsoft needs to fix

Internet Explorer is pre-installed on every Windows PC, even though it’s been superseded by Microsoft’s new Edge browser in terms of long-term support. The reason is simple: Many organizations use the archaic browser for legacy applications, and so Microsoft has had to keep it around but isn’t spending a great deal of time on improving it. Unfortunately, according to one security firm, Internet Explorer has a serious flaw that’s leaving it open to malware attacks.

ZDNet reports on the zero-day bug, which is coming from Chinese antivirus software company Qihoo 360 Core. The company’s security research team claim that the bug uses a Microsoft Office document that has a vulnerability installed that opens a web page that downloads a piece of malware. According to the researchers, the malware exploits a user account control (UAC) bypass attack, and it also utilizes file steganography, which is the technology of embedding a message, image, or file within another message, image, or file.

Qihoo 360 also reported on the bug via Twitter:

Recommended Videos

We uncovered an IE 0day vulnerability has been embedded in malicious MS Office document, targeting limited users by a known APT actor.Details reported to MSRC @msftsecresponse

— 360 Threat Intelligence Center (@360CoreSec) April 20, 2018

Please enable Javascript to view this content

Microsoft responded to ZDNet’s request for comment with the following rather generic statement:

“Windows has a customer commitment to investigate reported security issues, and proactively update impacted devices as soon as possible. We recommend customers use Windows 10 and the Microsoft Edge browser for the best protection. Our standard policy is to provide remediation via our current Update Tuesday schedule.”

The following image shows a basic flowchart of how the bug is executed on an affected system. Beyond this, there is not a great deal of information on the flaw and little else to go on in determining just how infected systems are impacted. Until Microsoft fixes the bug, of course, it will remain an issue for Windows users.

Qihoo 360

Apparently, the attack is being conducted globally by an “advanced persistent threat (APT) group.” That implies a group of hackers with some capabilities that can conduct such a sophisticated attack. Unfortunately, there is not much users can do at this point except follow the usual security advice: Keep your systems and software updated, make sure you’re using sufficient malware protection, and don’t open any files unless you’re absolutely certain that it’s from a trusted source and that it was sent on purpose.

Mark Coppock
Mark Coppock is a Freelance Writer at Digital Trends covering primarily laptop and other computing technologies. He has…
This secret Microsoft Edge feature changed the way I work
A photo of Microsoft Edge running on a Windows laptop

Microsoft Edge is my go-to web browser. As aggressive as Microsoft might be with pushing Edge on Windows 11 users over alternatives like Firefox and Google Chrome, it sure is useful compared to its competition.

Jam-packed with AI features thanks to Copilot and even memory-saving features like sleeping tabs, it's hard for me to use any other browser but Edge. But one thing I love about the browser is a secret feature that's pretty well kept in the sidebar — and it's called Drop.
Changing how I transfer files

Read more
Microsoft is already expanding Bing Chat to Skype and phones
Microsoft Edge browser showing Bing Chat on an iPhone.

Bing Chat, the AI chatbot powered by ChatGPT, is one of Microsoft's most exciting products, and the Windows developer is wasting no time in incorporating artificial intelligence into more of its products, including three of its mobile apps: Skype, Bing mobile, and Edge.

Microsoft announced the news in a blog post this morning. The Edge browser and the Bing app are obvious choices for adding AI-enhanced search, and early access users will begin seeing Bing Chat in those apps soon. We'd seen hints about Bing Chat on mobile, just two days ago, so Microsoft is moving quickly.

Read more
Microsoft finally, officially pulls the plug on Internet Explorer
An Internet Explorer desktop icon.

Happy Valentine's Day -- Internet Explorer is now dead. After announcing it would phase out the legacy browser last year, Microsoft announced that it permanently disabled Internet Explorer 11 on consumer versions of Windows 10.

The browser was available on Windows 10 previously, despite Microsoft noting that it was "retired" and "out of support." Windows 11 never shipped with Internet Explorer, with Microsoft moving to its new Edge browser.

Read more