Skip navigation.

exploreopera

| Help

Sign up | Help

For a Cool Web Surfing

Alerts, News, Tests, Scan Online, Threats... and more !

OS Windows : A new vulnerability discovered...

, , ,

Microsoft XMLHTTP ActiveX Control Code Execution Vulnerability

Secunia Advisory: SA22687

Release Date: 2006-11-04

Critical: Extremely critical

Impact: System access

Where: From remote

Solution Status: Unpatched

OS:

  • Microsoft Windows 2000 Advanced Server
  • Microsoft Windows 2000 Datacenter Server
  • Microsoft Windows 2000 Professional
  • Microsoft Windows 2000 Server
  • Microsoft Windows Server 2003 Datacenter Edition
  • Microsoft Windows Server 2003 Enterprise Edition
  • Microsoft Windows Server 2003 Standard Edition
  • Microsoft Windows Server 2003 Web Edition
  • Microsoft Windows XP Home Edition
  • Microsoft Windows XP Professional
  • Software: Microsoft Core XML Services (MSXML) 4.x

    Description:

    A vulnerability has been reported in Microsoft XML Core Services, which can be exploited by malicious people to compromise a users system.

    The vulnerability is caused due to an unspecified error in the XMLHTTP 4.0 ActiveX Control.

    Successful exploitation allows execution of arbitrary code when a user e.g. visits a malicious website using Internet Explorer.

    NOTE: The vulnerability is already being actively exploited.

    Solution:

    Microsoft has recommended various workarounds including setting the kill-bit for the affected ActiveX control (see the vendor's advisory for details).


    Go to Secunia website.

    Read the whole article.

    Mac OS X, Parasitic Virus FoundA New Anti-spam Group Formed

    Write a comment

    You must be logged in to write a comment. if you're not a registered member, please sign up.

    July 2008
    SMTWTFS
    June 2008August 2008
    12345
    6789101112
    13141516171819
    20212223242526
    2728293031