Month of ActiveX Bugs project reveals Office 2000 flaw

By
Follow google news

Microsoft is looking into reports of a flaw in Office 2000 disclosed as part of the Month of ActiveX Bugs (MoAxB) project.

Month of ActiveX Bugs project reveals Office 2000 flaw
A Microsoft spokesperson told SCMagazine.com that the Redmond, Wash.-based corporate giant is investigating vulnerability reports, but is not aware of any public attacks attempting to exploit the flaw.

The company "will take the appropriate action to protect our customers" after the investigation, according to the spokesperson, who said possible remedies may include a patch or advisory.

Microsoft encourages responsible disclosure of vulnerabilities, said the spokesperson.

The flaw was revealed Wednesday on the Month of ActiveX Bugs project blog in a post authored by the project’s creator, a hacker using the name shinnai.

Excessive data passed to the OUACTRL ActiveX control may result in a buffer overflow allowing the execution of arbitrary code or a DoS attack. The vulnerability was fixed in Microsoft Office 2000 Service Pack 3, according to a Wednesday advisory from US-CERT, which encouraged users to follow security best practices in response to reports.

MoAxB has now revealed 24 ActiveX flaws during the month of May. The latest of a growing list of "month of X bugs" projects, MoAxB has faced now-routine criticism from vendors and researchers that it has trampled on responsible disclosure practices.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

JB Hi-Fi Group finds new cyber security leader

JB Hi-Fi Group finds new cyber security leader

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft's July security patch fest brings on the 'bug apocalypse'

Microsoft's July security patch fest brings on the 'bug apocalypse'

Russian spies hunt for routers running legacy protocols with default credentials

Russian spies hunt for routers running legacy protocols with default credentials

Log In

  |  Forgot your password?