+ Reply to Thread
Results 1 to 2 of 2

Thread: Microsoft Admits IE Vulnerability

  1. #1

    Join Date
    24.03.09
    Location
    canada
    P2P Client
    emule
    Posts
    2
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 ssssssss2

    Microsoft Admits IE Vulnerability

    A security advisory has been issued by Microsoft, confirming a privately reported vulnerability in Microsoft Video ActiveX Control.

    The company acknowledged the attack on June 6 giving out details of the systems and versions of the Internet Explorer affected, along with workarounds for the same.

    Microsoft says that users running IE6 or IE7 on Windows XP and Windows Server 2003
    are vulnerable to the drive-bys attacks, while Windows Vista and Server 2008 and those running IE8 are not at risk.

    The Issue
    According to Microsoft, an attacker who successfully exploited the vulnerability in Microsoft Video ActiveX Control could gain the same user rights as the local user. When using Internet Explorer, code execution is remote and may not require any user intervention.
    Our investigation has shown that there are no by-design uses for this ActiveX Control in Internet Explorer which includes all of the Class Identifiers within the msvidctl.dll that hosts this ActiveX Control.

    Microsoft Recommends
    Microsoft says that users running IE6 or IE7 on Windows XP and Windows Server 2003 are vulnerable to the drive-bys attacks; a workaround for this is available here.

    On the other hand, Windows Vista and Server 2008 users and those running IE8 which are not at risk are also recommended that they remove support for this ActiveX Control within Internet Explorer using the same Class Identifiers as a defense-in-depth measure.

    Techtree News Staff, Jul 07, 2009 1511 hrs IST
    Vulnerability in Microsoft Video ActiveX Control
    Techtree.com India > News > Internet > Microsoft Admits IE Vulnerability, Gives Solution
    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    splicer (07.07.09)

  3. #2
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,439
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39439
    Please use the QUOTE tag.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •