In the wake of a series of cyberattacks that have leveraged zero-day vulnerabilities, Microsoft has recently made adjustments to the settings of its Microsoft Edge browser. Specifically, it has imposed stringent limitations on the convenient means of accessing Internet Explorer (IE) Mode. The primary objective behind this move is to thwart hackers from exploiting unpatched zero-day vulnerabilities within the Chakra JavaScript engine to launch malicious attacks.
Attackers typically devise deceptive websites with the intention of luring users into loading pages in IE Mode. Once users fall into this trap, the vulnerabilities are triggered, granting attackers the privilege of remote code execution. Subsequently, these attackers can escalate their privileges to gain control over the targeted devices.
To mitigate the risk of such attacks, Microsoft has eliminated various user-friendly methods of activating IE Mode. These include toolbar buttons, right-click menu options, and quick access entries in the main menu. As a result, activating IE Mode now necessitates a deliberate action on the part of the user. For the average user, this means manually adding web page addresses that are permitted to be loaded in IE Mode. However, it's worth noting that IE Mode configured through enterprise policies for business users remains exempt from this new restriction.
