Monday, November 6, 2006

New Windows XMLHTTP ActiveX Zero-Day Found

Via SecurityFocus -

Another new zero-day exploit for Microsoft systems has appeared, capable of compromising fully patched IE 6/7 systems when a user visits a malicious website.Microsoft has issued an advisory on the ActiveX vulnerability and exploit, first discovered by Secunia and labeled as "extremely critical." All Microsoft systems except Windows Server 2003 are vulnerable. Users may fall victim just by visiting a maliciously crafted website.Deflecting responsibility for the situation, Microsoft advises users affected by the zero-day exploit to, "contact their local FBI office or post their complaint on the Internet Fraud Complaint Center Web site. Customers outside the U.S. should contact the national law enforcement agency in their country." The vulnerability affects hundreds of millions of computer systems, however. Of those vulnerable, it is not known how many users will visit malicious websites that contain the exploit before an official patch appears from Microsoft.

Microsoft Security Advisory (927892)

Secunia Security Advisory (SA22687)

No comments:

Post a Comment