Tenable Research Release Highlights

Forum Discussion

justinhall's avatar
justinhall
Product Team
3 years ago

Updates to Detection of Microsoft Internet Explorer...

Updates to Detection of Microsoft Internet Explorer Unsupported Version

Plugin

22024 - Microsoft Internet Explorer Unsupported Version Detection

Target Release Date

May 23, 2023

Change

Microsoft recently released an update, KB5022834, that disables Internet Explorer 11 on Windows 10, redirecting users to Microsoft Edge. Nessus plugin 22024, which detects an unsupported version of Internet Explorer on the target host, will no longer fire when the target has this patch installed. 

Previously, the plugin would fire on all versions of Windows, but would not fire on a Windows machine if Internet Explorer had been redirected to Edge via Group Policy (“Computer Configuration/Administrative Templates/Windows Components/Internet Explorer/Disable Internet Explorer 11 as a standalone browser”.) or a registry setting (\HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Main\NotifyDisableIEOptions). This aspect of the plugin’s behavior will not change in this new release - three additional conditions to prevent the plugin from firing are being added:

  • The machine is running Windows 11
  • The machine is running Windows 10 and has KB5022834 installed
  • The machine has “Reload sites in IE mode“ disabled via Edge Browser Policy.

Impact

Customers will no longer see this vulnerability associated with Windows 11, or Windows 10 machines that have KB5022834 installed, or any machine with redirection to IE Mode disabled through Edge Browser Policy. Customers should note that files that traditionally would be associated with Internet Explorer are still present on the filesystem of Windows machines.

1 Reply

  • adam_walter's avatar
    adam_walter
    Connect Contributor II

    I'm finding this update isn't working. I'm not seeing a drop in the number of active vulnerabilities for plugin 22024 and it is still showing on a Windows endpoint that has the February 2023 (KB5022834) Microsoft patch installed.

    Is anyone else noticing the same, or different?