Feeds

Second unpatched ActiveX bug hits IE

Swiss cheese browser gains extra hole

The Power of One eBook: Top reasons to choose HP BladeSystem

Scallywags are using an unpatched vulnerability in an ActiveX component to distribute malware, Microsoft warned on Monday. The development adds to already pressing unresolved Internet Explorer security bug woes.

No patch is available for the Office Web Components ActiveX security hole, although there are workarounds which can be automated for enterprise rollouts. The flawed component is used by IE to display Excel spreadsheets, greatly increasing the scope for mischief. Win XP and Win 2003 systems are particularly at risk, while the additional security controls in Vista cover Microsoft's modesty.

Redmond said it's aware of attacks against the security bug, which would involve tricking users into visiting booby-trapped websites. McAfee warns of targeted Trojan attacks based on the vulnerability circulating in China.

The timing of the advisory, a day before Microsoft's monthly Patch Tuesday update, suggests it's highly unlikely that a fix will become available until August at the earliest.

Monday's advisory adds to the list of pending Internet Explorer vulnerabilities, most notably an unpatched flaw in Microsoft Video ActiveX Control that has become the target of widespread exploitation since earlier this month. The flaw is particularly serious because Internet Explorer users can get hit simply by straying onto a hacker-controlled website, providing they are running Windows XP. Vista, as with the latest ActiveX bug, is far less susceptible.

Six updates - three of which address critical flaws in Windows - are due from Microsoft later on Tuesday, as explained here. Redmond is expected to patch the more pressing (and longstanding) online video ActiveX bug later.

Nonetheless, the current outbreak of unpatched ActiveX bugs has prompted some security watchers, including the SANS Institute's Internet Storm Centre (here) and F-Secure (here), to advise punters to consider using alternative browsers in preference to Internet Explorer. ®

The Power of One eBook: Top reasons to choose HP BladeSystem

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
BMW's ConnectedDrive falls over, bosses blame upgrade snafu
Traffic flows up 20% as motorway middle lanes miraculously unclog
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.