Tue, Jul 07, 2009
Exploited ActiveX Vulnerability in Windows web browsers; workaround available
A security vulnerability in the Microsoft Video ActiveX control
has been discovered and is being actively exploited. This vulnerability
allows an attacker to create a malicious web page which, when browsed by
a Windows-based web browser, will run commands of the attacker's choosing
on the browsing machine. While a fix is not yet available, Microsoft
has published a workaround that (temporarily) disables the vulnerable
ActiveX control(s). This workaround is available from Microsoft at http://support.microsoft.com/kb/972890.
For more information, see http://www.kb.cert.org/vuls/id/180513
and
http://www.microsoft.com/technet/security/advisory/972890.mspx.
To be emailed any new alerts as they appear, or to cease being emailed such alerts, send email to securityalerts-request@cs.