Ie 9, 10 And 11

Discussion in 'Software' started by Imandy Mann, Jan 19, 2020.

  1. Imandy Mann

    Imandy Mann MajorGeekolicious

    I continue to see write-ups about patches needed to Windows because of, or directly to Internet Explorer. Can't remember the last time I used it and most any thread you read nowadays of anything related to online activity, the user is using a different browser.

    This week I see the NSA has put out warnings about a vuln making the rounds in browsers including IE. MS says their fix will come out in the Feb11 update. Till then use work-arounds and limit access to jscript.dll. - I sure most user can do this with a blindfold on!!

    Here's a partial note from 'EndGadget'.....

    The issue is significant enough that Homeland Security issued an advisory encouraging people to both be aware of the flaw and consider implementing workarounds, including temporarily restricting access to jscript.dll.

    Unlike the Firefox bug, though, you'll have to wait a while for a patch. Microsoft said it wasn't likely to provide its fix until its next monthly security release, slated for February 11th. Until then, you'll either have to consider workarounds or be cautious about clicking links to visit unfamiliar sites.

    .....

    In 10 I see both browsers, IE and Edge, come with the install.
    Is IE there because so much of the OS has needs IE code to function. Remember on earlier versions you could not just delete IE. Would mess up File Explorer and I don't know what else.
    So why don't MS just bury the code needed in the /system or /system32 folders and eliminate the public facing IE all together. Will this maybe be part of a future update, roll-up or whatever type fixes they come up with?
     
  2. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Here's why posted in another forum
    Here are his credentials in case you don't know Mr Goretsky.
    https://www.welivesecurity.com/author/goretsky/
    https://mvp.microsoft.com/en-us/PublicProfile/10023?fullName=aryeh goretsky

    Corporate Customers can pay for 3 years of additional support for Windows 7 so IE 11 will be around at least that long and patched (for paying users).
     
    Imandy Mann likes this.
  3. Imandy Mann

    Imandy Mann MajorGeekolicious

    And so with IE tied into the OS so deeply all Windows installs needs IE patched since a perp that gains access can exploit the vulns offered by IE whether it's even never been used on a certain pc. With '7 just past eos will it get this IE patch I wonder?
     
  4. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Imandy Mann likes this.
  5. Imandy Mann

    Imandy Mann MajorGeekolicious

    Hey, Thanks! Now there's a link that might be more helpful to a certain group of users compared to the info given in some of the more 'authoritative' tech and news articles out there just telling people to use a workaround and leave them dangling.......

    Great for those comfortable with the command prompt and using admin rights.
    I bet that leaves a lot of users just scratching their heads. I don't see anything that says if a perp finds a way in a system that they couldn't call their way into the jscript.dll vuln to furthur their damage. So I don't know if you have to be actively using IE.

    The MS page says in the "Impact of the Workaround" section that it only applies if your under 'elevated risk' already. Then it seems to say it only comes from websites using jscript in the scripting engine. And that '9, '10 and '11 use jscript9.dll anyway.

    So is this really so important and impacting on users for the NSA and Homeland Security to be putting out warnings? And MS can wait for 2 or 3 weeks? Sounds a lot less impacting than what is being put out.
     
  6. Imandy Mann

    Imandy Mann MajorGeekolicious

  7. Imandy Mann

    Imandy Mann MajorGeekolicious

  8. Eldon

    Eldon Major Geek Extraordinaire

    For someone to exploit any vulnerability in any Windows OS, they need access to that computer.
    Computer security is user dependent.
     
    baklogic likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds