Newsletter:

Skip Navigation LinksHome > News > Security > Microsoft issues advisory for ActiveX flaw

Microsoft issues advisory for ActiveX flaw

By Shaun Nichols
3 October 2006 09:45AM
Tags: microsoft | issues | advisory | activex | flaw

Vulnerability in Windows Shell could allow remote code execution.

Microsoft has issued a security advisory about a vulnerability that affects nearly all versions of Windows that the company still supports.

While the company claimed that it is not aware of any active exploits for the vulnerability, security advisory 926043 details the flaw in the WebViewFolderIcon ActiveX control in Windows Shell. 

According to Microsoft, the vulnerability could be exploited by viewing a maliciously-crafted HTML file.

Once the exploit has been launched, an attacker could execute code remotely on the compromised PC, including malware and spyware programs.

A spokesman said that a patch is set to be released as part of Microsoft's next scheduled update on 10 October.

Microsoft suggests several workarounds in the meantime, including setting Internet Explorer to ask permission before running ActiveX. This will cause frequent requests as a large number of sites use ActiveX controls.

The US Computer Emergency Response Team recommends users to avoid clicking on unsolicited or otherwise suspicious links. 

The SANS Internet Storm Centre suggests that users should think about switching from Internet Explorer to other web browsers. 

Microsoft said that versions of Windows Server 2003 and Windows Server 2003 Service Pack 1 with the Enhanced Security Configuration enabled were not affected by the vulnerability.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(6679) -  internet
(6423) -  iinet
(6397) -  copyright
(6397) -  afact
(5994) -  servers
(5994) -  mipi
(4847) -  telstra
(4534) -  broadband
(4470) -  nbn
(3010) -  internode
(2534) -  microsoft
(1888) -  network
(1492) -  software
(1470) -  data
(1372) -  google