Trend Micro Helps Affected Users Navigate Internet Explorer Zero-Day CVE-2014-1776 Vulnerability
Last Update: Monday, May 5, 2014 : 12:00 (+4GMT)
New rules and mitigation advice to tackle vulnerability affecting all versions of IE, especially Windows XP
Dubai, United Arab Emirates: Global leader in cloud security, Trend Micro Incorporated (TYO: 4704; TSE:4704), warns of and provides mitigation around the first Internet Explorer zero-day vulnerability – CVE-2014-1776 – which will remain unpatched in Windows XP. To protect users against exploits leveraging this vulnerability, Trend Micro has released two rules to help reduce the threat until a patch is provided by Microsoft, and to protect unsupported Operating Systems (“OS”) such as Windows XP. The deep packet inspection (“DPI”) rules available to customers of Trend Micro Deep Security and OfficeScan Intrusion Defense Firewall (“IDF”) include:
•1006030 – Microsoft Internet Explorer Remote Code Execution Vulnerability (CVE-2014-1776)
•1001082 0 – Generic VML File Blocker
Announced over the weekend via the Microsoft Security Advisory 2963983, the CVE-2014-1776 vulnerability is due to the way Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated. The successful exploitation of the vulnerability allows an attacker to execute arbitrary code in the context of the current user, allowing the attacker to run code on a victim system if the user visits a website under the control of the attacker.
Users can be lured into opening specially crafted webpages using the Internet Explorer by clickable links sent through emails or instant messages. The Adobe Flash file embedded in these malicious sites will then be used to bypass Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) protections on the target system. While attacks are only known against three IE versions 9 to 11, the underlying flaws exists in all versions of IE in use today, from IE 6 through to IE11.
“This vulnerability may linger unpatched in many systems for some time, as it is the first vulnerability affecting Windows XP systems that will not be patched. This means that for the millions of users still using this particular operating system, they will be left with a security hole that will never be fully fixed. The risk of using unsupported OS such as Windows XP is real, and this vulnerability is proof of that. We strongly encourage Windows XP users to migrate to a supported OS as soon as they can, and ensure their systems are protected as they plan for the migration,” comments , Macky Cruz , Security Focus Lead, Trend Micro Inc.
Users can reduce risk from this vulnerability by disabling or removing the Flash Player from IE whenever possible. In addition, Microsoft has also indicated some workarounds as part of their security advisory including the Enhanced Protected Mode for IE 10 and 11, deemed as one of the easiest workarounds in the advisory by Trend Micro security experts.
Protecting unprotected and under-protected systems
The end of support for any software, OS or not, leaves organizations more vulnerable to threats, but there are some solutions that can help address or mitigate this dilemma including:
•Virtual Patching: With the ability to “virtually patch” affected systems before actual patches are made available, virtual patching complements traditional patch management strategies reducing the risks to companies. Another benefit is that it can “virtually patch” unsupported applications. For example, Trend Micro Deep Security has been supporting Windows 2000 vulnerabilities even beyond its end of support.
•Enhanced Mitigation Experience Toolkit (EMET): Trend Micro threat security experts recommends using the EMET toolkit which prevents software vulnerabilities from being exploited through several security mitigation technologies, thereby reducing exploits from this vulnerability.
Cyber threats can have profound effects on companies. Trend Micro urges all IE users to stay vigilant and migrate away from Windows XP to a supported operating system, while ensuring their systems are always protected as they prepare for enterprise-wide migration.
- Joyalukkas Strengthens US Footprint with 8th Showroom in Iselin, New Jersey... [2216-Views]
- Mercato Takes Media on a Magical Summer Journey with The Grand Comedy Circus a... [1705-Views]
- Group-IB launches Purple Teaming service to close the gap between security inv... [1459-Views]
- Dubai Gears Up for a Spectacular Start to 29th Dubai Summer Surprises with Liv... [1188-Views]
- Government of Fujairah Signs Agreement to Purchase Gasoline Production from Et... [993-Views]
- Spain Defeats Argentina to Claim Second FIFA World Cup Title... [954-Views]
- MAIR Group and Makani Real Estate Announce Mall of Al Ain Redevelopment and Ex... [950-Views]
- EGA wins the AI Vision and Strategy Award at the 2026 Manufacturing Leadership... [928-Views]
- The New SHEGLAM Lashlighter Root-Up Lash Primer Gets to the Root of the Matter... [867-Views]
- G-SHOCK MTG-B4000BD-1A: A New Language of Structural Beauty... [853-Views]
- Dubai Summer Surprises: Shop, Save, and Win as the Great Dubai Summer Sale Arr... [849-Views]
- Bogdan guskov brings his perfect finishing record to ufc® fight night abu dhab... [816-Views]
- Dubai Municipality and Enviroserve sign strategic agreement to enhance e-waste... [807-Views]
- Commercial Bank of Dubai prices USD 550 million Additional Tier 1 perpetual no... [793-Views]
- Standard Chartered: "UAE Business Activity to Accelerate in Q3 2026"... [763-Views]
- AutoPro and Chevrolet extend UAE mega promotion offering four vehicle prizes u... [763-Views]
- Maserati previews Project GT4 at Goodwood Festival of Speed 2026... [760-Views]
- Grab discounts of up to 90% as the Great Dubai Summer Sale kicks off tomorrow ... [730-Views]
- Drillcube Opens EMEA Hub in Dubai — Bringing the Underground Mining One-Stop-S... [730-Views]
- Ministry of Finance Announces Pilot Phase of the Electronic Invoicing System a... [727-Views]




