blog web hosting internet
Green Web Hosting
17.03.10
97 Best Practices of Pricing Page Designs #webdesign http://ping.fm/BhlUQ
17.03.10
Starting Out Organized: Website Content Planning The Right Way http://ping.fm/duNcI
17.03.10
6 Things Social Media Can%u2019t Do for Your Business http://bit.ly/dfTNVa
17.03.10
Questions That Help Assess Website Usability #webdesign http://ping.fm/Sdhbi
16.03.10
Learn Photoshop: All of the Basics for Beginners http://ping.fm/MIzR8
16.03.10
IE9 May Actually Be a Fantastic Browser http://ping.fm/mo4i3
16.03.10
CSS In Depth: Floats & Positions http://ping.fm/I9LAH
16.03.10
10 Features to Look Forward to in #WordPress 3.0 #cms http://ping.fm/GBZQD
16.03.10
10 #WordPress plugins to work with images #cms http://ping.fm/5d10d
16.03.10
What Every Designer Should Do Right Now #webdesign http://ping.fm/jvK20
15.03.10
Showcase of Well Designed Websites http://ping.fm/S5z9k
15.03.10
Get to Know the WordPress Hierarchy http://ping.fm/4qz0F
15.03.10
Final Day Sale - Free Hosting Offer http://ping.fm/yekjj
13.03.10
24 Beautiful Web Designs Across the Color Spectrum http://ping.fm/kNdxb
12.03.10
Call To Action Buttons: Guidelines, Best Practices And Examples #webdesign http://ping.fm/4FvOq
12.03.10
Top 10 Best JavaScript Books that Beginners should Read http://ping.fm/jfTWE
11.03.10
Find Your Favorite Design Communities on Facebook | MyInkBlog http://ping.fm/k6XRr
11.03.10
4 Days Remaining - Free Hosting Offer http://ping.fm/SViLi
11.03.10
Showcase of 30 Beautiful Blog Designs http://ping.fm/Vb9mC
11.03.10
RocketTheme - Professional #Joomla Template Club http://ping.fm/u57YJ
Microsoft Video ActiveX Control Vulnerability PDF Print E-mail
Blog - Security
Monday, 06 July 2009 20:40

National Cyber Alert System

Technical Cyber Security Alert TA09-187A

Microsoft Video ActiveX Control Vulnerability

 

 

Original release date: July 06, 2009

Source: US-CERT

Systems Affected

* Microsoft Windows XP

* Microsoft Windows Server 2003

 

Overview

 

An unpatched vulnerability in the Microsoft Video ActiveX control

is being used in attacks.

 

 

I. Description

 

Microsoft has released Security Advisory (972890) to describe

attacks on a vulnerability in the Microsoft Video ActiveX control.

Because no fix is currently available for this vulnerability,

please see the Security Advisory and US-CERT Vulnerability Note

VU#180513 for workarounds.

 

 

II. Impact

 

A remote, unauthenticated attacker could execute arbitrary code

with the privileges of the victim user.

 

 

III. Solution

 

Apply workarounds

Microsoft has provided workarounds for this vulnerability in

Security Advisory (972890). Additional details and workarounds are

provided in US-CERT Vulnerability Note VU#180513.

The most effective workaround for this vulnerability is to set kill

bits for the Microsoft Video ActiveX control, as outlined in the

documents noted above. Other workarounds include disabling

ActiveX, as specified in the Securing Your Web Browser document,

and upgrading to Internet Explorer 7 or later, which can help

mitigate the vulnerability with its ActiveX opt-in feature.

 

IV. References

 

* US-CERT Vulnerability Note VU#180513 -

<http://www.kb.cert.org/vuls/id/180513>

 

* Microsoft Security Advisory (972890) -

<http://www.microsoft.com/technet/security/advisory/972890.mspx>

 

* Securing Your Web Browser -

<http://www.us-cert.gov/reading_room/securing_browser/>

 

 


busy
 
blog comments powered by Disqus
Disclosure: Content posted to this site is in no way an endorsement for a product or service and may result in compensation from the vendor. Some content contained in this site is syndicated content.