Microsoft warns of hole in Video ActiveX control

By Elinor Mills, CNET News.com
Tuesday, July 07, 2009 09:38 AM

Microsoft on Monday warned of a vulnerability in its Video ActiveX Control that could allow an attacker to take control of a PC if the user visits a malicious Web site.

There have been limited attacks exploiting the hole, which affects Windows XP and Windows Server 2003, Microsoft said on its Security Response Center blog.

This is the second DirectShow security hole Microsoft has announced in the past few months. The company has yet to provide a security update for a vulnerability announced in May that involves the way DirectX handles QuickTime files.

Since there are no by-design uses for the ActiveX Control within Internet Explorer, Microsoft is recommending that users implement a workaround outlined in the security advisory. Customers can automatically implement the workaround by following the instructions under "Fix It For Me" in the Knowledge Base article for advisory number 972890 on the

Even though Windows Vista and Windows Server 2008 are not affected by the vulnerability, Microsoft is recommending that users of those products also use the workaround.

Microsoft is working on a security update and will release it when the quality is at the appropriate level for broad distribution, the company said.

The Microsoft Video Control object is an ActiveX control that connects Microsoft DirectShow filters for use in capturing, recording, and playing video. The control is the main component used in Windows Media Center for building filter graphs for recording and playing television video.

When it is used in IE, the control can corrupt the system state in such a way that arbitrary code could be run by an attacker. If the user is logged in with administrative rights, the attacker could take complete control of the system.

Antivirus vendor Symantec said it was seeing the flaw being exploited in China and other parts of Asia and cited reports that indicate thousands of Web sites are hosting the exploit.

Internet Explorer versions 6 and 7 are at risk, but people running IE 8 are not vulnerable, Symantec said.

This article was first published as a blog post on CNET News.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

Most WinXP IE Users Unprotected from Ongoing Attacks
Good News: one has to go to a compromised website to be attacked. Although its also possible one can click on a link in an email via Outlook/Outlook Express

Bad News: if the only thing protecting your PC is an ordinary anti-virus/spyware products, you probably won't be protected if you're attacked.

www.tucows.com...

More bad news: more ActiveX controls to disable. BTW, after patches were implemented, did you re-enable the ActiveX controls you disabled last times?

www.blueridgenetworks.com...

Still more bad news: last month tens of thousands of webservers were compromised so as to deliver attacks like these on visitors.

www.blueridgenetworks.com...

Happy Trails
Posted by Eirik Iverson on Tuesday, July 07 2009 09:46 PM


Tech Jobs Now!

Search for your ideal tech job:

OpenAmplify developer's diary - part three: Topic intention comparisons

Web Development

Justin James chronicles his process of using Hapax's OpenAmplify Web service to create an application that can match documents with content that is similar or identical to the source document.


Read more »



 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




What Y2K can teach us about 2012

Blog thumbnail

Dec. 21, 2012. It's a big day on the calendar, particularly because some believe it marks the last day of the world as we know it. The apocalypse. Armageddon.

The..... by Eileen Yu

Read more »

Tags

  1. antivirus
  2. apple ipod
  3. cnet networks inc.
  4. desktop
  5. e - mail
  6. hard drive
  7. intuit inc.
  8. mcafee inc.
  9. microsoft corp.
  10. microsoft windows
  11. microsoft windows vista
  12. microsoft windows xp
  13. norton co.
  14. pc
  15. performance
  16. security
  17. software
  18. tool
  19. web
  20. web site