Zero-day hackers vs Microsoft

A Zero-day exploit is “an unknown exploit that divulges security flaws in software before such a flaw is publicly reported or announced”(Ibor). It is hard to combat a Zero-day exploit, since there isn’t a security patch that is pushed out to fix the vulnerability. Usually, once the exploitation is discovered, the owner of the software pushes out a patch to prevent further attacks. However, in this case Microsoft was notified before the exploit was made public and still failed to take action. According to a recent article by ZDnet, a researcher discovered a Zero-Day vulnerability that lets hackers steal files from Windows. He informed Microsoft of the vulnerability. However, Microsoft did not patch the problem in its upcoming monthly security update. The Zero-Day exploit uses a vulnerability within the way Internet Explorer processes MHT files. Without the patching, hackers can exploit the vulnerability and steal files from you systems. This discovery highlights a few things, first the importance of regular patching, and second the need to have a cyber security expert on your side giving you advice. For now, we recommend you avoid Internet Explorer until Windows pushes out a patch for the problem. Once the patch is pushed, make sure you update you system.

As you can see patching/updating system is a critical process for any business that utilizes a computer system on a daily bases. Here at DGM, we have a systematic patching process that will support your patch management needs. Please reach out to us at for more information.

