Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft patches final Pwn2Own IE bug

Microsoft patches final Pwn2Own IE bug

Ron Ron
September 19, 2019
1 min read

Microsoft has patched the last vulnerability in Internet Explorer discovered by a researcher in March of 2011 during the Pwn2Own hacking contest. The researcher, who also won $15,000 for his discovery, exploited a vulnerability in IE so that he could insert malware onto the computer.

“Yes MS11-057 patches the final bug, the protected mode bypass, that I used in my Pwn2Own exploit, the other two being a use-after-free which was patched in MS11-018 and an information leak patched in MS11-050,” Stephen Fewer of Harmony Security stated. Fewer was the guy who discovered this flaw during Pwn2Own.

Microsoft gives credit to Fewer for discovering this flaw, but the company isn’t really classifying it as a security flaw. “Yes, this update addresses a Protected Mode bypass issue, publicly referenced as CVE-2011-1347.”

Fewer was able to utilize three exploits to bypass IE’s sandbox, which is called Protected Mode. Doing so, Fewer was able to insert malware onto the computer.

As far as next year’s Pwn2Own, Fewer adds, “I don’t have any plans as of yet for next year’s competition, but if I have a few new bugs handy closer to the time, who knows?”

The update to this vulnerability is included in August’s Patch Tuesday updates, including MS11-057 for IE, and can be downloaded and installed via the Microsoft Update and Windows Update.

Further reading: Internet Explorer, Pwn2Own

Share this article:
Tags:
Internet Explorer Pwn2Own
Previous Article Rumor: iOS 5 will be a ‘major revamp,’ won’t debut until fall Next Article Queen’s Awards double for RealVNC

Related Articles

Chrome and Gemini icons representing Gemini Live voice assistant integration in Chrome

Chrome tests Gemini Live voice assistant in a floating overlay panel

March 14, 2026

Chrome’s Organizer feature may sync Gemini and AI conversations across devices

March 14, 2026

After Chrome, Edge tests launching the browser automatically when you sign into Windows

March 13, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy