Skip the navigation

Microsoft to patch IE10 Pwn2Own bugs next week, says security expert

Slates nine security updates for IE, Windows, SharePoint and Defender on Windows 8, RT

April 4, 2013 03:35 PM ET

Computerworld - Microsoft today said it will ship nine security updates next week, two rated "critical," to patch Internet Explorer (IE), Windows, SharePoint Server, Office Web Apps and the company's anti-malware software in Windows 8 and RT.

One security expert put his money on the IE update as the most important of the pending, in part because he expects Microsoft to fix the flaws revealed a month ago at the Pwn2Own hacking contest.

"Microsoft will patch the vulnerability from Pwn2Own [in IE10]," said Andrew Storms, director of security operations at Tripwire. "It has to. If it doesn't, it would be no better off than it was before, when it patched IE every other month."

Storms was referring to the two vulnerabilities that a team from the French firm Vupen exploited at Pwn2Own. Vupen won $100,000 for demonstrating the exploit of IE10 on Windows 8 Pro running on a Surface Pro tablet.

The bugs, Vupen said four weeks ago, existed in both the desktop version of IE10 on Windows 8 as well as in the "Modern"-style browser that runs on the tile-based user-interface (UI) once dubbed "Metro."

Google and Mozilla patched the vulnerabilities disclosed in their Chrome and Firefox browsers within hours of the contest, but Microsoft has yet to issue a post-Pwn2Own fix for IE.

April's Patch Tuesday will be on par with Microsoft's releases in 2013, which have averaged nine each month thus far in the year. Last year, the monthly average was 6.9 updates, Storms said.

Two of the updates will be ranked critical, Microsoft's top threat rating, while the remaining seven will be tagged as "important," the next ranking below critical.

Like last month, the most notable was the one that will patch all supported versions of IE, including the 12-year-old IE6, IE7, IE8, IE9 and also the newest, IE10. "Bulletin 1," as the update was identified today in Microsoft's monthly advance warning of the upcoming updates, affects IE10 on Windows 7, Windows 8 and Windows RT.

It will be the first critical update to IE10 on Windows 7 since the new browser was launched on that operating system in late February.

Next week's IE patches will be the fourth month in a row that Microsoft has quashed bugs in its browser, and the ninth month out of the last 10 with an IE update. Last July, Microsoft announced it had beefed up the IE security and patching teams, and would be able to issue monthly updates rather than every other month, as had been its practice for years.

Also on next week's agenda will be a critical update to all client editions of Windows except for Windows 8 and Windows RT; those will be unaffected, Microsoft said.

Our Commenting Policies