Microsoft released security update 3034682 to address 41 vulnerabilities in Internet Explorer 6 through 11, including multiple flaws that could allow remote code execution if a user visited a specially crafted webpage. The most severe issues could let an attacker run code with the same privileges as the current user, making the risk highest on systems where users have administrative rights. Microsoft rated the bulletin Critical for affected Windows client systems and Moderate for affected Windows server systems.
The bulletin said one flaw, CVE-2015-0071, had been exploited in the wild, while CVE-2014-8967 had been publicly disclosed before the patch was issued. Microsoft said the update corrects memory corruption and permission-validation issues, improves ASLR behavior, and strengthens cross-domain policy enforcement. It also noted that systems running Internet Explorer 9, 10, and 11 require updates 3021952 and 3034196 for full protection, with 3023607 and, on some platforms, 3036197 also potentially installed automatically.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
Microsoft published Security Bulletin MS15-019, a separate critical security bulletin from the MS14-056, MS14-065, MS15-009, MS15-018, and MS15-032 entries already in the timeline. This represents a distinct Microsoft vulnerability disclosure and patch release event.
Microsoft published Security Bulletin MS15-018, a separate critical security bulletin from the MS14-056, MS14-065, MS15-009, and MS15-032 entries already in the timeline. This represents a distinct Microsoft vulnerability disclosure and patch release event.
Microsoft published Security Bulletin MS14-056, a separate critical security bulletin from the MS14-065, MS15-009, and MS15-032 entries already in the timeline. This represents a distinct Microsoft vulnerability disclosure and patch release event.
Microsoft published Security Bulletin MS14-052, a separate critical security bulletin from the MS14-056, MS14-065, MS15-009, MS15-018, MS15-019, and MS15-032 entries already in the timeline. This represents a distinct Microsoft vulnerability disclosure and patch release event.
Microsoft published Security Bulletin MS14-051, a distinct critical security bulletin not already represented in the existing timeline. This constitutes a separate Microsoft vulnerability disclosure and patch release event.
Microsoft published Security Bulletin MS14-037, a distinct critical security bulletin not already represented in the existing timeline. This constitutes a separate Microsoft vulnerability disclosure and patch release event.
Microsoft published Security Bulletin MS14-035, a distinct critical security bulletin not already represented in the existing timeline. This constitutes a separate Microsoft vulnerability disclosure and patch release event.
Microsoft published Security Bulletin MS14-029 as a distinct critical security bulletin. This constitutes a separate Microsoft vulnerability disclosure and patch release event not already represented in the timeline.
Microsoft published Security Bulletin MS14-021 as a distinct critical security bulletin. This constitutes a separate Microsoft vulnerability disclosure and patch release event not already represented in the timeline.
Microsoft published Security Bulletin MS14-018 as a distinct critical security bulletin. This constitutes a separate Microsoft vulnerability disclosure and patch release event not already represented in the timeline.
Microsoft published Security Bulletin MS14-010, a distinct critical security bulletin not already represented in the existing timeline. This constitutes a separate Microsoft vulnerability disclosure and patch release event.
Microsoft published Security Bulletin MS14-012 as part of its March 2014 security releases. The bulletin is listed as Critical for many client platforms and Moderate for many server platforms, affecting multiple supported Windows versions.
Microsoft published Security Bulletin MS15-032, a separate critical security bulletin from MS15-009. This represents a distinct Microsoft vulnerability disclosure and patch release event.
On March 4, 2015, Microsoft revised bulletin MS15-009 to clarify installation details for related updates required for full protection on Internet Explorer 9, 10, and 11. The revision noted dependencies involving updates 3021952 and 3034196, with additional updates 3023607 and in some cases 3036197 potentially installed automatically.
On February 10, 2015, Microsoft published Security Bulletin MS15-009 and released security update 3034682 for Internet Explorer. The update addressed 41 vulnerabilities in Internet Explorer 6 through 11, including a publicly disclosed flaw and an exploited vulnerability, with the most severe issues allowing remote code execution via a specially crafted webpage.
Microsoft published Security Bulletin MS14-065, a separate critical security bulletin from the MS15-009 and MS15-032 entries already in the timeline. This represents a distinct Microsoft vulnerability disclosure and patch release event.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
go.microsoft.com
Open sourcego.microsoft.com
Open sourcego.microsoft.com
Open sourcego.microsoft.com
Open sourcego.microsoft.com
Open sourcego.microsoft.com
Open sourcego.microsoft.com
Open sourcetechnet.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.