A security researcher has published exploit code for the latest Internet Explorer zero-day flaw on the Web and Microsoft is warning that more attacks against the unpatched vulnerability can be expected in-the-wild. One thing seems to be more apparent with each passing Internet Explorer (IE) vulnerability: its time to upgrade the Web browser.
This zero-day exploit of Internet Explorer is just the most recent demonstrating that IE8 is more secure than its predecessors--especially IE6. Security aside, Web hosts and developers generally despise IE6 as well. For evidence of this fact you need look no further than the extensive list of supporters displayed on the IE6nomore.com site.
IE6 is Not Secure
Joshua Talbot, Security Intelligence Manager, Symantec Security Response agreed "IE 6 does not have the security features implemented in later versions of IE; for example, Data Execution Prevention (DEP) and Protected Mode. DEP makes it more difficult for attackers to successful exploit memory corruption vulnerabilities, while Protected Mode limits what an attacker can do if they are able to gain control of the IE process."
This is the part where many readers stop reading and jump over to the comments to express their opinion--sometimes quite passionately--that everyone should just stop using Internet Explorer completely and that anyone who chooses to continue using IE as their Web browser deserves the issues and security concerns that come with it.
Judging from the Web browser market share trends, there are many who subscribe to the "drop Internet Explorer" mantra. Microsoft has seen steady--although minute--declines in market share month after month, while rival Web browsers such as Firefox and Chrome continue to make gains. Still, Microsoft holds a dominant stake at almost 62 percent--more than double the share held by second-place Firefox.
If you drill a little deeper in the browser market share data, though, you will find that not only is Internet Explorer the number one browser, but IE8 specifically is at the top of the list with more than 22 percent of the browser market. Not too shabby for a browser that will celebrate its one-year anniversary next week.
What is concerning is that the number two browser is the nine year old IE6 at almost 20 percent of the market. Although IE7 has been available for almost four years, it is the number four browser, coming in behind Firefox 3.5 with a meager 13.57 percent.
Wean Off of IE6
IE6 is simply not secure and businesses and IT administrators should make it a priority to upgrade the Web browser as soon as possible. The Web is a major vector for cyber attacks and the Web browser is the Achilles heel that makes organizations vulnerable and creates the weakest link in the security chain.
Of course, it's not quite that easy. Many organizations that still rely on IE6 would like to make the switch to IE8 but can't. Kandek explained "In the corporate environment, software is managed, and IE6 or IE7 are part of the initial, approved build that works on all internal applications. Requalifying that build against all internal applications is a large effort that many companies do not have resources for."
"If they do, they might find applications that specifically use IE6 features that are incompatible with other browsers. Recently one of our larger customers told me that they had dozens of applications that do not run under IE8," continued Kandek.
Symantec's Talbot shared the same concerns "For enterprises, not only is there a cost to purchase software, there is also the cost to deploy and maintain. An enterprise must quality-assure software to ensure the new version meets the current needs and that there are no compatibility issues. They must also allocate IT resources to deploy the update. Then there is also an education component that must be provided for users to address differences between versions and how to handle known compatibility issues."
A Microsoft spokesperson commented via e-mail to say "Microsoft has consistently recommended that consumers upgrade to the latest version of our browser. Internet Explorer 8 offers improvements in speed, security and reliability as well as new features designed for the way people use the web. While we recommend Internet Explorer 8 to all customers, we understand we have a number of corporate customers for whom broad deployment of new technologies across their desktops requires more planning."