Microsoft restricts IE mode after hackers exploit zero-day flaw

Microsoft has tightened access to Internet Explorer (IE) mode in its Microsoft Edge browser after discovering that hackers were exploiting a critical zero-day vulnerability to take control of users’ computers.

Gareth Evans, head of security for Microsoft Edge, said the company’s threat intelligence team received reports that cybercriminals were using IE mode to compromise devices through a previously unknown flaw.

Although Internet Explorer was officially retired on June 15 2022, Microsoft retained IE mode within Edge to allow legacy websites and enterprise systems relying on outdated technologies such as ActiveX or Flash to continue functioning.

Investigations revealed that the attackers were not targeting Edge directly but instead using a social engineering strategy combined with a zero-day vulnerability in Chakra, the old JavaScript engine once used by Internet Explorer. This flaw allowed malicious code to be executed remotely without the user’s knowledge.

The attack typically began with hackers creating fake but convincing websites designed to trick users into visiting them. Once on the page, users would be prompted to ‘reload this page in Internet Explorer mode’. When the option was activated, the Chakra zero-day vulnerability was triggered, enabling the attackers to escalate privileges and gain full control over the victim’s computer.

What makes the situation more concerning is that Microsoft has yet to release a patch for the Chakra engine vulnerability. As a precaution, the company has now removed all shortcuts for enabling IE mode – including toolbar buttons, right-click menus and options in the main browser menu.

For those who still need to use IE mode, users must now manually enable it via Settings ? Default Browser ? Allow sites to be reloaded in Internet Explorer (IE) mode, switching from Default to Allow. They must then add the URLs of specific sites that require IE mode.

Microsoft said the change is aimed at increasing security and ensuring that IE mode is used only for trusted sites specified by the user, making it more difficult for hackers to exploit fake or malicious websites.

Leave a Reply

Your email address will not be published. Required fields are marked *