The Register®

Original URL: http://www.theregister.co.uk/2006/09/18/ie_flaw_warnings_grow/

Warnings grow over unpatched IE flaw

Stop us if you've heard this before

By John Leyden

Posted in Security, 18th September 2006 15:43 GMT

Watch Now : Virtual Machine Movement with Hyper-V

Security experts warn a new, unpatched vulnerability in Internet Explorer might be used to spread malware. A flaw in Microsoft's Direct Animation Path (daxctle.ocx) ActiveX control, rated as critical [1] by Secunia and other security watchers, has spawned [2] proof of concept code but has not yet become the subject of widespread, hostile attack. Memory corruption is possible [3] even on a fully patched Windows XP system.

A patch is unlikely until next month's Patch Tuesday update. Microsoft said it was investigating [4] the problem. Surfers are advised to restrict which sites they allow to run ActiveX controls or here [5] ActiveX controls altogether. Tech-savvy IE users might try a workaround from the SANS Institutes's Internet Storm Centre, as explained here [6]. A simpler solution, at least until Microsoft releases a patch, might be to use Firefox, Opera or all any other alternative browser. ®