dslreports logo
site
 
    All Forums Hot Topics Gallery
spc

spacer




how-to block ads


Search Topic:
uniqs
1327
share rss forum feed

Parad0X787
"If U know neither the enemy nor yoursel
Premium
join:2013-09-17
Edmonton, AB

1 recommendation

BTW, "Microsoft rushes out security patch for IE"

Normally, Microsoft releases security bulletins for software products on the second Tuesday of each month. That happened last week as scheduled, but today the company announced it has rushed out an additional patch designed to fix an exploit that has been found in Internet Explorer, and is being used in attacks on IE8 and IE9.

In a post on its security response blog, Microsoft says the issue would allow a hacker to launch a remote code execution if a person surfs to a website using IE that contains malicious code. The blog adds, "There are only reports of a limited number of targeted attacks specifically directed at Internet Explorer 8 and 9, although the issue could potentially affect all supported versions. "

The company has released a "Fix-it" patch, "CVE-2013-3893 MSHTML Shim Workaround" to plug this security hole in all currently supported versions of IE. In addition, Microsoft recommends that users set their security settings on the web browser to "High" to block any ActiveX Controls and Active Scripting on websites. It also recommends users set up IE so that it informs them ahead of time before running any Active Scripting features. The company plans to release a full security patch that will be a more complete solution to this problem in the near future.

Source: Microsoft | Image via Microsoft


redwolfe_98
Premium
join:2001-06-11
kudos:1

1 recommendation

Re: BTW, "Microsoft rushes out security patch for IE"

here is a related thread:

»Microsoft Security Advisory Notification - Sept 17, 2013


Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:4
reply to Parad0X787

That sounds like a quote from a third party (not Microsoft) but you don't provide the source.

You also provide no link to the MSRC blog.
--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson


Parad0X787
"If U know neither the enemy nor yoursel
Premium
join:2013-09-17
Edmonton, AB

Indeed ..... U R right, try to include fair use third party LINK but mod rules change ¿ ¿ Would like to provide MS direct LINK too


Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:4

Yes, the rules have changed. But I believe that if you had not just quoted a part of an article from another site, but had used a SMALLER quote AND added some comment of YOUR OWN to your post abut this whole issue, what your opinion is, whether not you have installed the hot fix (I have hesitated to install it), whether or not you use EMET to mitigate, etc. THEN my understanding is that a link to both the third party article and Microsoft security response blog would be acceptable.
--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson


Parad0X787
"If U know neither the enemy nor yoursel
Premium
join:2013-09-17
Edmonton, AB
reply to Parad0X787

THX 4 your pointer, SORRY my first day join DSL forum & indeed EMET protected my IE 10, just my wife IE 9 need to be safe first !!! Here we go : MS direct LINK
»blogs.technet.com/b/msrc/archive···ted=true


Parad0X787
"If U know neither the enemy nor yoursel
Premium
join:2013-09-17
Edmonton, AB
reply to Mele20

THX 4 your pointer, SORRY my first day join DSL forum & indeed EMET protected my IE 10, just my wife IE 9 need to be safe first !!!



siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17

1 edit
reply to redwolfe_98

NM


Parad0X787
"If U know neither the enemy nor yoursel
Premium
join:2013-09-17
Edmonton, AB

1 recommendation

Hi ..... Randy, nice to C U aeound



Cartel

join:2006-09-13
Chilliwack, BC
kudos:2
Reviews:
·TekSavvy DSL
·Shaw
·TELUS

1 edit
reply to Parad0X787

Sidebar uses mshtml.dll also....
I thought I'd be safe because IE8 is "uninstalled".
Apparently not.



Edit:

The exploit was attacking a Use After Free vulnerability in IE’s HTML rendering engine (mshtml.dll) and was implemented entirely in Javascript (no dependencies on Java, Flash etc), but did depend on a Microsoft Office DLL "hxds.dll"

Guess I'm ok...no office here.



siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17
reply to Parad0X787

Likewise, I know you from [...]


Parad0X787
"If U know neither the enemy nor yoursel
Premium
join:2013-09-17
Edmonton, AB

>> ....



antdude
A Ninja Ant
Premium,VIP
join:2001-03-25
United State
kudos:4
reply to Parad0X787

Re: BTW, "Microsoft rushes out security patch for IE"

No OOTB update yet?



StuartMW
Who Is John Galt?
Premium
join:2000-08-06
Galt's Gulch
kudos:2
Reviews:
·CenturyLink

1 edit

Re: BTW, "Microsoft rushes out security patch for IE"

That would be on Tues 9/24. Patch Tues = 2nd Tues of month. Emergency patch Tues = 4th Tues of month

»en.wikipedia.org/wiki/Patch_Tuesday

quote:
Sometimes there is an extraordinary Patch Tuesday, 14 days after the regular Patch Tuesday.
--
Don't feed trolls--it only makes them grow!


antdude
A Ninja Ant
Premium,VIP
join:2001-03-25
United State
kudos:4
Reviews:
·Time Warner Cable

said by StuartMW:

That would be on Tues 9/24. Patch Tues = 2nd Tues of month. Emergency patch Tues = 4th Tues of month

»en.wikipedia.org/wiki/Patch_Tuesday

quote:
Sometimes there is an extraordinary Patch Tuesday, 14 days after the regular Patch Tuesday.

MS has done OOTB on other days too. I think the last one was on a Friday!
--
Ant @ AQFL.net and AntFarm.ma.cx. Please do not IM/e-mail me for technical support. Use this forum or better, »community.norton.com ! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer.

Parad0X787
"If U know neither the enemy nor yoursel
Premium
join:2013-09-17
Edmonton, AB
reply to antdude

Re: BTW, "Microsoft rushes out security patch for IE"

No sign from MS, nor on MS-forum too



antdude
A Ninja Ant
Premium,VIP
join:2001-03-25
United State
kudos:4
Reviews:
·Time Warner Cable

said by Parad0X787:

No sign from MS, nor on MS-forum too

Oh well, I guess we will have to wait for one of the Tuesdays then. :P


siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17
Reviews:
·Bell Sympatico
reply to Parad0X787

Re: BTW, "Microsoft rushes out security patch for IE"

quote:
Microsoft is scheduled to distribute its monthly patch release Oct. 8. Because the software maker has released a temporary fix for the flaw affecting all versions of IE, experts do not expect a permanent fix until the upcoming release.
»www.csoonline.com/article/740657···ie-flaw?

Libra
Premium
join:2003-08-06
USA
kudos:1

1 recommendation

Thank you Randy for letting us know when an update will be available to fix this.

Sincerely, Libra


andyross
Premium,MVM
join:2003-05-04
Schaumburg, IL
reply to Parad0X787

MS better get a patch out soon. The exploit is now in the wild:
»arstechnica.com/security/2013/10···he-wild/



siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17
Reviews:
·Bell Sympatico

A fair bit of FUD out ATM, me thinks: see »news.cnet.com/8301-1009_3-576056···attacks/ Those with the Fix It in place should be fine until Tuesday.



norwegian
Premium
join:2005-02-15
Outback
Reviews:
·WestNet Broadband


Isn't the fixit only for x86 (x32) and cannot be applied to x64?

Not sure if that is a programming issue or the exploit won't work with x64's extra protection?
Which has me wondering??
--
The only thing necessary for the triumph of evil is for good men to do nothing - Edmund Burke


Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:4

Tabs run as 32bit even when using IE 64bit browser. So, even though the FixIt is applied only to 32bit IE seems to me it would prevent the exploitation on IE 64bit also. I haven't applied it though.
--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson


Frodo

join:2006-05-05

said by Mele20:

Tabs run as 32bit even when using IE 64bit browser.

I'm not seeing that. In task manger, 32 bit tasks have a "*32" appended after it. With 3 tabs open, I see 4 iexplore.exe processes, the broker, or housing process and 3 tab processes. When I add a tab, I see an additional IE process.


On the other hand, I have the option of running the 32 bit IE. When I run the 32 bit version with 3 tabs, I see 4 IE processes with a *32 appended to them


I think if the "fixit" is run, it will protect the 32 bit IE but you're out of luck with the 64 bit one. On Windows 7, the user can pick between a 32 bit and 64 bit IE.

My fixit is to run Palemoon.

Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:4

Click for full size
My Task Manager shows IE running as 64 bit with the tabs inside it running as 32 bit. Its always been like this since I got this computer. We've had discussions about it before here.

"In Internet Explorer on the Desktop, by default, Content Processes remain at 32bit by default for compatibility with 32bit ActiveX controls, Toolbars, BHOs, etc. Even when you directly launch the 64bit iexplore.exe executable, you will still have a 64bit Manager Process that hosts only 32bit Content Processes. If you want to enable 64bit Content Processes for the Desktop, you must tick the Enable Enhanced Protected Mode option in the Security section of Internet Explorer’s Tools > Internet Options > Advanced tab. When this option is enabled, all Content Processes that are running in Protected Mode (e.g. Internet Zone and Restricted Zone, by default) will begin to use 64bit Content Processes."

»blogs.msdn.com/b/ieinternals/arc···top.aspx

I assume you have enabled Enhanced Protected Mode in IE 10 64bit and it works correctly. I have Enhanced Protected Mode enabled for Internet and Restricted Zones but I see the tabs as 32bit whether in those zones or the Trusted Zone where Enhanced Protected Mode is turned off.

The Fixit wouldn't be needed if the tabs are running as 64bit with Enhanced Protected Mode in effect.
--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson

Frodo

join:2006-05-05

I'm still on IE9. Since it ain't broke, I ain't fixing it. Anyway, your task manager looks different from mine. I don't see icons in the process list.

I still think the situation is ambiguous. I recommend that if the user wants to use IE, use the 32 bit one.
»support.microsoft.com/kb/2887505

quote:
The Fix it solution that is described in this section applies only 32-bit versions of Internet Explorer.

I suppose the 64 bit thing might call the 32 bit thing and so forth, but I recommend going with the plain language. Use the "32-bit versions of Internet Explorer".

Now, if the EMET approach is the sole approach in dealing with this issue, then I don't think it matters.

Edit: My OS is Win7-pro

Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:4

I have to apologize. I started this confusion as I failed to state I was talking about IE 10 on Windows 8. Plus, I didn't realize at first that you are on Windows 7.
--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson


Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:4
reply to norwegian

said by norwegian:

Isn't the fixit only for x86 (x32) and cannot be applied to x64?

Not sure if that is a programming issue or the exploit won't work with x64's extra protection?
Which has me wondering??

Yeah, the Fixit is for 32bit IE only so says Microsoft. What that implies regarding the invincibility of IE64bit running in Enhanced Protected Mode on Windows 8 I have no idea.

I am even further confused by the fact that while I am running IE64bit, the tabs in the Internet zone and Restricted Zone, which should be running as 64bit since I enabled Enhanced Protect Mode for those zones a long time ago, still run as 32 bit (assuming Task Manager is correct and I double checked with Process Monitor).

So, should I apply it to IE 64bit with Enhanced Protected Mode enabled or not?
--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson

Frodo

join:2006-05-05

said by Mele20:

I am even further confused by the fact that while I am running IE64bit, the tabs in the Internet zone and Restricted Zone, which should be running as 64bit since I enabled Enhanced Protect Mode for those zones a long time ago, still run as 32 bit ...

Found this.
»www.eightforums.com/tutorials/24···8-a.html
quote:
UAC must be enabled to be able to have 64-bit IE10. Otherwise, it will be 32-bit IE10 even if set to 64-bit in this step.

I don't know the current status of your UAC, but I remember you saying you didn't like it in the past. You could check that aspect to see if that will enable 64 bit processes.

I also see from the same people.
»www.sevenforums.com/tutorials/28···7-a.html
quote:
In 64-bit Windows 7, Internet Explorer 10 (IE10) has 32-bit and 64-bit together in one browser now.

I'm glad I didn't upgrade. IE9 makes it nice and simple. I can pick between 32 and 64 bit and I'm done.

Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:4

Aha! Yes, I tried to get along with UAC but it was driving me nuts particularly with regards to HostsMan. It might not be a problem almost a year later and several newer versions of HostsMan later. I finally disabled UAC entirely in the registry. I did not know that it needed to be enabled in order for IE10 64 bit with Enhanced Protected Mode to actually force the tabs to run as 64bit. I am glad to have that mystery solved.

I can enable UAC (will have to anyway if I want to download 8.1 as the Metro apps don't work if UAC is disabled but I don't use them so that didn't matter to me but would if I need to access the Microsoft Store to get 8.1).

It's ironic that it was a tutorial at eightforums that explained how to disable UAC and I read it (and other tutorials on Windows 8 there) but I never saw the one about IE10 64 bit Enhanced Protected Mode on Win 8. If I leave UAC disabled, then I guess my question is answered. The housing may be IE 64bit but tabs are 32bit so I would need to install the Fixit. But then I read this:

"Note:
The Fix it patch only applies to 32-bit versions of IE. For those using 64-bit IE, they would have to wait until Microsoft releases an appropriate software update. In the meantime, they are advised to use browsers other than IE."

»blogs.quickheal.com/wp/critical-···crosoft/

ARRRH! I think I will just pull all my hair out. Or just not use IE until Microsoft issues a a security patch. It's not my default browser so I can just avoid it for another week as even if I enable UAC so that Enhanced Protected Mode works and the tabs start running in 64bit, I still don't know if that protects against this exploit.

--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson