Malware writers take aim at new ActiveX vulnerability

 

Microsoft Internet Explorer vulnerable.

Microsoft is advising customers to take additional security precautions following the discovery of new attacks targeting Internet Explorer.

The company said that the attacks exploit a vulnerability in an ActiveX control for the Microsoft Office Web Components software.

By embedding a specially-crafted spreadsheet file within a web page, an attacker can cause an application crash and gain the access rights of the current user, potentially allowing for remote code execution on the target system.

The ActiveX vulnerability is the second such flaw to be attacked in recent days. Last week, the company issued a warning over another attack taking aim at a flaw in the Microsoft Video control.

Microsoft is providing an automatic workaround which disables the vulnerable component. The company did not give information on when a permanent fix will be released.

News of the latest flaw comes on the eve of the company's planned monthly patch release. In its advance notice announcement, the company said that it would be issuing fixes for no fewer than six security flaws.

Because the new alert has surfaced so close to the planned 'Patch Tuesday' release, security experts have suggested that the company is unlikely to issue a fix along with the monthly update and users are being advised to run the automatic workaround procedure.

Copyright ©v3.co.uk


Malware writers take aim at new ActiveX vulnerability
"Interesting since since this is classed as a vulnerability, that when you click on the "automatic workaround" link you will see the following:- THIS AFFECTS Microsoft Office Small Business ..."
By ADSLNerd
 
 
 
Comments: 1
ADSLNerd
Jul 14, 2009 7:24 PM
Interesting since since this is classed as a vulnerability, that when you click on the "automatic workaround" link you will see the following:-

THIS AFFECTS
Microsoft Office Small Business Accounting 2006
Microsoft Office 2003 Web Components for the 2007 Microsoft Office system
Microsoft Office 2003 Service Pack 3
Microsoft Office 2003 Web Components
Microsoft Internet Security and Acceleration Server 2004 Standard Edition

Plus notice the word "could" not "will" or "most likely will". The only current software affected appears to be Office 2007. The rest relate to older software, so if you have newer / updated software you shouldnt have an issue.
Comments have been disabled for this article.
 
 
 
Top Stories
The New Zealand telco problem
Opinion: Could Telstra save Kiwi telcos?
 
IT price probe to 'name and shame' gougers
Industry ducking the issue, committee claims.
 
Revealed: 2012 e-government award winners
Government highlights projects, professionals of the year.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Should the Government enact new legislation to protect copyright holders in the digital age?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 477

Vote