LOGO
Reply to Thread New Thread
Old 07-07-2009, 09:14 PM   #1
eFDMBwKH

Join Date
Oct 2005
Posts
515
Senior Member
Default Microsoft Warns Of 'Browse-And-Get-Owned' Attack
Microsoft Warns Of 'Browse-And-Get-Owned' Attack
Attacks have been reported that attempt to exploit an unpatched vulnerability in Microsoft's Video ActiveX Control.

By Thomas Claburn
InformationWeek
July 7, 2009 01:55 PM

Microsoft (NSDQ: MSFT) on Monday issued a security advisory about a zero-day vulnerability in the Microsoft Video ActiveX Control. The flaw could allow a remote unauthenticated attacker to execute malicious code on computers running Windows XP and Windows 2003 Server.

"A browse-and-get-owned attack vector exists," acknowledged Microsoft security engineer Chengyun Chu on the company's Security Research & Defense blog. "A user needs to be lured to navigate to a malicious Web site or a compromised legitimate Web site to be affected. No further user interaction is needed."

http://www.informationweek.com/news/...es+and+threats
eFDMBwKH is offline


Old 07-07-2009, 10:47 PM   #2
Luisabens

Join Date
Oct 2005
Posts
437
Senior Member
Default
This link provides a work around patch that disables the Active X control that is causing the problem.

http://blogs.technet.com/srd/archive...idctl-dll.aspx

Microsoft Security Advisory on this subject is here:
http://www.microsoft.com/technet/sec...ry/972890.mspx
Luisabens is offline


Old 07-07-2009, 10:51 PM   #3
sterofthemasteool

Join Date
Oct 2005
Posts
455
Senior Member
Default
Thanx for the links nline! Patch installed and I rest easy now....
sterofthemasteool is offline


Old 07-07-2009, 10:56 PM   #4
mikelangr

Join Date
Oct 2005
Posts
622
Senior Member
Default
You are welcome but read the attached links. There are side issues with the patch. It isn't a fix just a bypass and that is a bit of a kludge.
mikelangr is offline


Old 07-07-2009, 11:15 PM   #5
hwood

Join Date
Oct 2005
Posts
341
Senior Member
Default
Like I've always heard, 50% of something is better than 100% of nothing!
hwood is offline


Old 07-08-2009, 11:54 AM   #6
attlawqa

Join Date
Oct 2005
Posts
377
Senior Member
Default
Thanks Nline, I hope you will post if they get an actual "fix" for it. I installed the "bypass" for now on my desktop that runs XP.
attlawqa is offline



Reply to Thread New Thread

« Previous Thread | Next Thread »

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

All times are GMT +1. The time now is 03:51 PM.
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 PL2
Design & Developed by Amodity.com
Copyright© Amodity