NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


ActiveX Is Vulnerable to Attacks Even Without Vulnerabilities

Claims Symantec

By Marius Oiaga, Technology News Editor

11th of August 2008, 14:51 GMT

Adjust text size:


Windows Vista Security
Enlarge picture
Internet Explorer users are vulnerable to attacks targeting ActiveX, even when ActiveX is vulnerability-free, claims security company Symantec. According to Symantec's Sean Hittel, attackers have found a way to essentially serve users the vulnerability prior to exploiting it. Targeted is a critical security flaw in the ActiveX Control for the Snapshot Viewer for Microsoft Access.
Microsoft has patched the vulnerability via a security bulletin issued in July 2008, but the update was deployed only on the systems with the software installed. Symantec claims that all Internet Explorer users are vulnerable to the issue.

"Recently, we came across a rather unfortunate exploit case for the Access Snapshot Viewer ActiveX Vulnerability that took advantage of a property of the ActiveX system to exploit IE users who did not have the vulnerable control installed. How does one exploit a vulnerability that does not exist on a system you say? Sadly, attackers have found a way to install the vulnerable Access Snapshot Viewer ActiveX control through Internet Explorer prior to exploiting it," Hittel stated.

Symantec indicated that the control is signed and as such its insulation is completely silent. In fact, in order to become vulnerable no user interaction is required. The attackers' aim is to install the vulnerable control on the targeted computers, and then exploit the associated vulnerability.

"Once this vulnerable control is installed on the victim's computer, it is exploited in the same way as if the control was installed all along. To top it off, this attack is carried out as a drive-by attack, so the unprotected user may never know that they were vulnerable, or had been targeted, let alone infected," Hittel stated.

Microsoft's ActiveX technology is a notorious vector for attacks due to its ubiquity and distribution model. Symantec has warned that the silent ActiveX installations, part of the core of ActiveX operation, contribute to exposing end users to security risks.

TAGS:

ActiveX | Internet Explorer | ActiveX Control | Snapshot Viewer for Microsoft Access | vulnerability
Read by 1,480 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


New XP SP3 and Vista SP1 DirectX 9.c and 10.1 Downloads Available

The Future of Windows Is Manycore/Multicore

Microsoft Touts New Source of Windows 7 Information

Insight into the New Microsoft Vulnerability Exploitability Index

From Vista SP1 and XP SP3, Windows Update Coming to Windows Mobile

Vista SP1 and XP SP3 vs. Mac OS X and Linux

Microsoft Points the Finger at the Apple OS X Insecure Update Mechanism

XP SP3 RC1 and RC2 Still Available for Download

XP SP3 and Vista SP1: DirectX 9 and DirectX 10 Patches Updated

Broken Windows XP SP3 Installation Scenarios

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM