The Mountain-Ear logo
Log in Subscribe

Microsoft Security Warnings for Windows and Internet Explorer

Posted

Gail Eddy, Nederland. It’s been a busy time for Microsoft Security. First, they took down all support for Windows 7 on January 14th. And, if you are still using Win7 you saw a warning message pop up on your screen that Tuesday morning. 

Microsoft Security – Windows 10: And then, also on January 14th,  the National Security Agency (NSA) tells us that Windows 10 has a major security breach.

“On January 14, Microsoft released a set of patches for the Windows platform. While all of the issues addressed in the patch release are serious, this article will discuss one of them: CVE-2020-0601. Above anything else, we urge everyone to take action and patch their systems. CVE-2020-0601 is a serious vulnerability, because it can be exploited to undermine Public Key Infrastructure (PKI) trust. PKI is a set of mechanisms that home users, businesses, and governments rely upon in a wide variety of ways. The vulnerability permits an attacker to craft PKI certificates to spoof trusted identifies, such as individuals, web sites, software companies, service providers, or others. Using a forged certificate, the attacker can (under certain conditions) gain the trust of users or services on vulnerable systems, and leverage that trust to compromise them.”

I don’t pretend to know what this security breach does, but I do know that if you are using Windows 10 and you haven’t downloaded and installed the latest Windows 10 updates, you need to do that right now! And, if you’re still using Windows 7, check out our recent article: www.GeekForHireInc.com/keep-windows-7.

Internet Explorer: And, now we find out that Internet Explorer also has a major vulnerability. Cybersecurity and Infrastructure Security Agency (CISA) reports:

“Microsoft has released a security advisory to address a critical vulnerability in Internet Explorer. A remote attacker could exploit this vulnerability to take control of an affected system. According to the advisory, ‘Microsoft is aware of limited targeted attacks.’”

Since 2014, CISA has recommended that people not use Internet Explorer, but use a different browser instead:

“US-CERT is aware of active exploitation of a use-after-free vulnerability in Microsoft Internet Explorer. This vulnerability affects IE versions 6 through 11 and could allow unauthorized remote code execution. US-CERT recommends that users and administrators review Microsoft Security Advisory 2963983 for mitigation actions and workarounds. Those who cannot follow Microsoft’s recommendations, such as Windows XP users, may consider employing an alternate browser.”

Our recommendation?  Never use Internet Explorer.  Use Firefox!

Conclusion: Make sure you have your anti-virus set to automatically check everything you do.  At least once a week, you should also run a virus scan to make extra sure that your machine is good to go.

Information about Geek For Hire, Inc. Chris Eddy of Geek For Hire, Inc. has been providing computer service to families and small businesses with Mac’s and PCs for the past eighteen years. Angie’s List and the BBB rate Geek For Hire very highly.  You can find more on our website, or give us a call 303-618-0154. Geek For Hire, Inc. provides onsite service (Tier 3 support) to the Denver / Boulder / Front Range area as well as remote service throughout North America.

(Originally published in the February 13, 2020, print edition of The Mountain-Ear.)