International Cyber Expo International Cyber Expo
  • About Us
Saturday, 10 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Microsoft patches Internet Explorer zero-day

by The Gurus
November 22, 2013
in Editor's News
Share on FacebookShare on Twitter

Among eight patches released yesterday by Microsoft, the zero-day in Internet Explorer was finally covered after in the wild attacks were reported.

Released last night on its monthly Patch Tuesday, MS13-080 now patches two vulnerabilities that are in the wild and as described in Security Advisory 2887505, an attacker who successfully exploited these vulnerabilities could gain the same rights as the current user running Internet Explorer.
Wolfgang Kandek, CTO of Qualys, said: “This fixes ten vulnerabilities, including CVE-2013-3893, the zero-day that Microsoft originally acknowledged in September as having limited and targeted attacks in Asia. Since the volume continued to stay low, even after Metasploit added their implementation, Microsoft opted for a normal release schedule during Patch Tuesday, which places the least stress on IT organisations.
“MS13-080 also addresses CVE-2013-3897 in an interesting case that illustrates the concurrent discoveries of vulnerabilities. The vulnerability underlying CVE-2013-3897 was found internally at Microsoft and would have been fixed in MS13-080 as part of the normal security engineering and hardening that the product undergoes constantly.
“However, in the last two weeks, attacks against the same vulnerability became public, again limited and targeted in scope, but since the fix was in the code already, it enabled Microsoft to address the vulnerability in record time.”
Ross Barrett, senior manager of security engineering at Rapid7, said: “It’s been an interesting month for the Microsoft Security watchers of the world. If your job depends on securing systems running Windows, you should be eagerly awaiting the patch for the Internet Explorer (IE) 0-day (CVE-2013-3893: SetMouseCapture Use-After-Free) vulnerability in today’s Patch Tuesday (MS13-080).
“Exploitation of this vulnerability was detected first in targeted, regionally restricted exploitation, and then later in broader use once the exploit code spread to various public sites. Hopefully users have applied the Microsoft FixIt and/or EMET mitigations, and maybe even tested them with the Metasploit module that came out last week.
“Now, that’s not to say that the remaining eight IE vulnerabilities are not potentially just as bad or worse. However, at least at this time, they are not known to be in use.”
Lamar Bailey, director of security research and development at Tripwire, said: “So far these bugs are only being exploited in limited attacks, but users are still strongly encouraged to patch IE as soon as possible. Now that a patch is available we expect to see a rise in the number of attacks using these vulnerabilities.”
Of the remaining seven patches, three are classified as critical and four as important.
ShareTweet
Previous Post

Avast announce they beat DNS hackers in real time

Next Post

European Cybercrime Centre appoints cyber crime advisory board

Recent News

Attackers exploit AhsayCBS backup flaws to deploy disguised crypto miners

Attackers exploit AhsayCBS backup flaws to deploy disguised crypto miners

October 9, 2026
WorkNest Launches WorkNest Secure to Expand Cybersecurity and Compliance Services

WorkNest Secure Achieves CREST STAR-FS Accreditation for Red Teaming

October 8, 2026
Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds

Global cyber attacks up 48% as ransomware and phishing climb, Check Point finds

October 8, 2026
Filigran event

Filigran announces speakers for first THREAD event

October 8, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol