Microsoft bug
The latest ActiveX flaw could allow remote code execution

Malware writers take aim at new ActiveX vulnerability

Microsoft warns of new attack dangers

Shaun Nichols in San Francisco

Microsoft is advising customers to take additional security precautions following the discovery of new attacks targeting Internet Explorer.

The company said in a Security Advisory that the attacks exploit a vulnerability in an ActiveX control for the Microsoft Office Web Components software.

Embedding a specially-crafted spreadsheet file within a web page could allow an attacker to cause an application crash and gain the access rights of the current user, potentially allowing for remote code execution on the target system.

The ActiveX vulnerability is the second such flaw to be attacked in recent days. Microsoft issued a warning last week about attack taking aim at a flaw in the Microsoft Video control.

Microsoft has provided an automatic workaround which disables the vulnerable component, but did not give information on when a permanent fix will be released.

News of the latest flaw comes on the eve of the company's planned monthly patch release. Microsoft said in its advance notice that it will be issuing fixes for six security flaws.

However, the new alert has surfaced so close to the planned Patch Tuesday release that security experts believe Microsoft is unlikely to issue a fix along with the monthly update, and are advising users to run the automatic workaround procedure.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Seoul

Third wave of attacks hits South Korea

But North Korea not on the list of countries suspected of launching the assaults

MS bug

Microsoft responds to criticism over late fix

Flaw in ActiveX Control first reported in early 2008

Conficker still dominating attack landscape

Botnet accounted for two-thirds of attack traffic in Q1

Koobface worm resurfaces

Twitter accounts suspended as bogus tweets infest the micro-blogging site

Related white papers

Related jobs

Most watched

San Francisco

Views from the Valley: Oracle and HP square off over Hurd

A look at the major stories from the US

ViewSonic ViewPad 7

ViewSonic ViewPad 7 video

Hands on with 7in tablet that features phone capability and Android 2.2

Analysis and Reports

Storage-as-a-Service: Best efforts or best practice?
IDG research: IT professionals understand the fundamentals of managing and protecting data, but do not apply best practices

The seven security myths of Microsoft Windows 7
It is essential to separate myth from reality about the built-in security of Microsoft’s latest offering

Poll

VMworld 2010 poll

VMworld 2010 poll

How advanced is your firm's cloud computing strategy?

View poll results

White paper library

Attachmate

Smartstream

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Windows XP

Dell sounds death knell for Windows XP

PC maker to stop offering Microsoft OS on new kit...

Salesforce Chatter

Salesforce Chatter coming to iPhones and BlackBerrys

Enterprise social networking tool to be available on the go

San Francisco

Views from the Valley: Oracle and HP square off over Hurd

A look at the major stories from the US

Nokia N8

Nokia unveils price and release date of N8 smartphone

Hotly anticipated device to retail for £429 SIM free from...

Primary Navigation