Microsoft warns of attacks on new ActiveX hole

By Elinor Mills, CNET News.com
Tuesday, July 14, 2009 11:19 AM

Attackers are exploiting a new critical ActiveX hole in Microsoft Office to take control of PCs by luring Internet Explorer users to malicious Web sites, Microsoft said on Monday.

The zero-day hole, the third one announced by Microsoft in less than two months, is in Office Web Components ActiveX controls used to display and publish spreadsheets, charts, and databases to the Web.

It affects Office XP, Office 2003, Internet Security and Acceleration Server 2004 and 2006, as well as Office Small Business Accounting 2006.

The security advisory details a manual workaround, or people can use Microsoft's Fix-It tool to implement the workaround automatically.

Microsoft said it was working on a security update to patch the hole.

Antivirus vendor Sophos, meanwhile, said in a blog posting on its site that it had received reports of several Web sites, mostly in China, serving the exploit as part of a Web exploit kit that downloads and runs a Windows Executable detected as "Mal/Generic-A".

This article was first published as a blog post on CNET News.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

Microsoft warns of attacks on new ActiveX hole
ActiveX attacks are yesterday's nightmares if you prepare for them:

www.blueridgenetworks.com...

People keep asking me if limited user accounts (LUA) protect them from drive-by download attacks, well:

www.blueridgenetworks.com...
Posted by Eirik Iverson on Friday, July 17 2009 03:57 AM


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web