Information Security News mailing list archives

What do we know about the big, scary, exploited, emergency-patched IE security hole CVE-2019-1367?


From: InfoSec News <alerts () infosecnews org>
Date: Thu, 26 Sep 2019 09:34:12 +0000 (UTC)

https://www.computerworld.com/article/3440523/what-do-we-know-about-the-big-scary-exploited-emergency-patched-ie-security-hole-cve-2019-1367.html

By Woody Leonhard
Columnist
Computerworld
September 25, 2019

Microsoft set the patching world on its ear on Monday when it released an "out of band" patch to fix a vulnerability known as CVE-2019-1367. Susan Bradley raised the alarm immediately. I chimed in a few hours later with more details.

Then, yesterday (Tuesday), Microsoft dumped its usual big bunch of "optional, non-security" Win10 patches and "Monthly Rollup Previews" which — we finally figured out — include the fix for CVE-2019-1367. I wrote about that in Computerworld.

Microsoft's official description of CVE-2019-1367 sounds like a zillion other descriptions:

[...]
--
Subscribe to InfoSec News
https://www.infosecnews.org/subscribe-to-infosec-news/
https://twitter.com/infosecnews_

Current thread: