All the latest UK technology news, reviews and analysis

Update: Microsoft falls through XML flaw

by Clement James

07 Nov 2006

Be the first to comment

  • Tweet this
Microsoft
Microsoft is investigating reports of a vulnerability in the XMLHTTP 4.0 ActiveX Control

Security experts at Symantec issued a warning yesterday about an exploit spotted in the wild for an as yet unpatched vulnerability in Microsoft's XML core services.

Virus analyst Eric Chien warned that all supported versions of Internet Explorer, including IE7, make use of this functionality and are likely to be possible vectors of attack.

Microsoft issued a statement on Friday saying that it was investigating public reports of a vulnerability in the XMLHTTP 4.0 ActiveX Control. The company is "aware of limited attacks attempting to use the reported vulnerability".

"While the exploit has been spotted in the wild, it has only been seen on a single website and Symantec has no confirmed infection reports from customers. Nevertheless, as always, be cautious when surfing the web," said Chien.

Symantec has already released a signature, Bloodhound.Exploit.96, to catch this exploit.

Microsoft said that an attacker would have to host a website that contains a page used to exploit this vulnerability, largely through persuading victims to visit the site.

An attacker who successfully exploited this vulnerability could gain the same user rights as the logged on user.

Users whose accounts are configured to have fewer user rights on the system should therefore be less affected than users who operate with administrative rights.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Business Objects Developer - VP - Banking

Business Objects Developer - VP - Banking My leading...

C++ Engineers *Math Minds* Worcster £35k

C++ Programmer/ Developer/Object Orientated/ Software...

IMMEDIATE! Senior Java Design Developer - Banking

Senior Java Design Developer Banking / J2EE...

Internet Solutions Architect - Hands-on Banking experience

Internet Solutions Architect - Hands-on Banking experience...

To send to more than one email address, simply separate each address with a comma.