{"id":13127,"date":"2020-02-13T00:13:00","date_gmt":"2020-02-12T23:13:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=13127"},"modified":"2024-10-05T18:41:04","modified_gmt":"2024-10-05T16:41:04","slug":"internet-explorer-security-update-kb4537767-feb-2020","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/02\/13\/internet-explorer-security-update-kb4537767-feb-2020\/","title":{"rendered":"Internet Explorer Security Update KB4537767 (Feb. 2020)"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/11\/IE.jpg\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/?p=228174\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]Microsoft also released the KB4537767 cumulative security update for Internet Explorer on February 11, 2020. Here is some information about this update.<\/p>\n<p><!--more--><\/p>\n<h2>The vulnerability CVE-2020-0674 in IE<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg01.met.vgwort.de\/na\/17081df3c1be470d8667442fb3c9d9be\" width=\"1\" height=\"1\">Cumulative security update KB4537767 for Internet Explorer patches the 0-day vulnerability CVE-2020-0674, which was reported in mid-January 2020. This vulnerability was discovered by Cl\u00e9ment Lecigne of the Google Threat Analysis Group and Ella Yu of Qihoo 360. <\/p>\n<blockquote>\n<p>There is a memory corruption vulnerability in the scripting engine used by Internet Explorer. When objects are executed by the Scripting Engine in Internet Explorer, memory overflows or corruption may occur. As a result, attackers can use prepared Web pages to corrupt IE's memory in such a way that remote code can be infiltrated and executed. <\/p>\n<\/blockquote>\n<p>I had reported in the blog post <a href=\"https:\/\/borncity.com\/win\/2020\/01\/18\/warning-0-day-vulnerability-in-internet-explorer-0117-2020\/\">Warning: 0-Day vulnerability in Internet Explorer (01\/17\/2020)<\/a>. I also described the workaround, suggested by Microsoft, within this blog post. But the workaround causes some collateral damage, mentioned within my post.<\/p>\n<h2>Update KB4537767 for Internet Explorer<\/h2>\n<p>On 11 February 2020, Microsoft then released the cumulative security update <a href=\"https:\/\/support.microsoft.com\/help\/4537767\/\" target=\"_blank\" rel=\"noopener noreferrer\">KB4537767<\/a> for Internet Explorer. The update applies to the:<\/p>\n<ul>\n<li>Internet Explorer 11 at&nbsp;\n<ul>\n<li>Windows Server 2012 R2,\n<li>Windows Server 2012,\n<li>Windows Server 2008 R2 SP1,\n<li>Windows 8.1 Update and\n<li>Windows 7 SP1<\/li>\n<\/ul>\n<li>Internet Explorer 10 at Windows Server 2012\n<li>Internet Explorer 9 at Windows Server 2008 SP2<\/li>\n<\/ul>\n<p>The security update is part of the monthly rollup updates for Windows 7 SP1 and Windows 8.1 and their server counterparts. In Windows 10, the security update for Internet Explorer is also delivered with the cumulative security update for the respective Windows version. If you install security-only updates for Windows 7 SP1 and Windows 8.1 and their server counterparts, you must take care of installing the update yourself. <\/p>\n<ul>\n<li>The cumulative security update KB4537767 for Internet Explorer 11 is available on Windows Server 2012 and in Windows Embedded 8 Standard via Windows Update.\n<li>For other versions of Windows, the KB4537767 cumulative security update for Internet Explorer is available for manual download from the <a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=KB4537767\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Update Catalog<\/a> for manual installation.\n<li>In addition, the KB4537767 cumulative security update for Internet Explorer is available via WSUS for distribution in enterprise environments.&nbsp; <\/li>\n<\/ul>\n<p>In <a href=\"https:\/\/web.archive.org\/web\/20220922093739\/https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-patches-actively-exploited-internet-explorer-zero-day\/\" target=\"_blank\" rel=\"noopener noreferrer\">this article<\/a>, the colleagues from Bleeping Computer have prepared a table with the respective KB packages that contain updates for the respective Windows variant. However, note the notes in the support article for <a href=\"https:\/\/support.microsoft.com\/help\/4537767\/\" target=\"_blank\" rel=\"noopener noreferrer\">KB4537767<\/a> regarding the known issues and constraints associated with the update.&nbsp;&nbsp; <\/p>\n<h2>Important: Undo the mitigation workaround in IE<\/h2>\n<p>Anyone who has applied the workaround specified by Microsoft in mid-January 2020 to mitigate the 0-day vulnerability (see this Microsoft article about the 0-day vulnerability) must reverse this workaround before installing the update.&nbsp; <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">If you changed the permissions for JScript.dll to workaround the IE vulnerbility disclosed January, you need to undo it before applying security updates this month. If you don't know what I'm talking about, carry on.. <a href=\"https:\/\/twitter.com\/hashtag\/MEMCM?src=hash&amp;ref_src=twsrc%5Etfw\">#MEMCM<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/SCCM?src=hash&amp;ref_src=twsrc%5Etfw\">#SCCM<\/a> <a href=\"https:\/\/t.co\/TqUt6HU1Vo\">https:\/\/t.co\/TqUt6HU1Vo<\/a><\/p>\n<p>\u2014 Julie Andreacola (@jandreacola) <a href=\"https:\/\/twitter.com\/jandreacola\/status\/1227651603383144450?ref_src=twsrc%5Etfw\">February 12, 2020<\/a><\/p><\/blockquote>\n<p><span id=\"preserve5f0f6382b03c47eaafff8057bc94f92a\" class=\"wlWriterPreserve\"><SCRIPT charset=\"utf-8\" src=\"https:\/\/platform.twitter.com\/widgets.js\" async><\/SCRIPT><\/span> <\/p>\n<p>Microsoft employee Julie Andreacola points this out in the above tweet. Otherwise, problems with the update installation could occur.<\/p>\n<p><strong>Similar articles:<br \/><\/strong>Adobe Flash Player 32.0.0.330 released<br \/>Microsoft Office Patchday (February 4, 2020)<br \/><a href=\"https:\/\/borncity.com\/win\/2020\/02\/12\/microsoft-security-update-summary-february-11-2020\/\">Microsoft Security Update Summary (February 11, 2020)<\/a><br \/>Patchday Windows 10-Updates (February 11, 2020)<br \/><a href=\"https:\/\/borncity.com\/win\/2020\/02\/12\/patchday-updates-for-windows-7-8-1-server-feb-11-2020\/\">Patchday: Updates for Windows 7\/8.1\/Server (Feb. 11, 2020)<\/a><\/p>\n<p><a href=\"https:\/\/borncity.com\/win\/2020\/01\/18\/warning-0-day-vulnerability-in-internet-explorer-0117-2020\/\">Warning: 0-Day vulnerability in Internet Explorer (01\/17\/2020)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Microsoft also released the KB4537767 cumulative security update for Internet Explorer on February 11, 2020. Here is some information about this update.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[872,580,22],"tags":[42,2273,69,195],"class_list":["post-13127","post","type-post","status-publish","format-standard","hentry","category-browser","category-security","category-update","tag-internet-explorer","tag-kb4537767","tag-security","tag-update"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/13127","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=13127"}],"version-history":[{"count":3,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/13127\/revisions"}],"predecessor-version":[{"id":35553,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/13127\/revisions\/35553"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=13127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=13127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=13127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}