Windoze 0-day Bug

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Dr Mordrid
    Moderator
    • Apr 2001
    • 26592

    #1

    Windoze 0-day Bug



    Security researchers have identified an unpatched vulnerability in Windows. The flaw - which affects all supported versions of Windows bar Windows 2003 - resides in a security bug in Microsoft XML Core Services, specifically an unspecified security bug in the XMLHTTP 4.0 ActiveX Control.

    The flaw creates a means for hackers to inject malware onto the PCs of surfers running IE who visit a website hosting malicious code that attempts to harness the security bug. Security notification firm Secunia says that the vulnerability is being actively exploited by hackers.

    Microsoft has posted an advisory conceding the problem and suggesting possible workarounds, which basically involve disabling the affected ActiveX control, ahead of the arrival of a patch.
    Dr. Mordrid
    ----------------------------
    An elephant is a mouse built to government specifications.

    I carry a gun because I can't throw a rock 1,250 fps
  • Technoid
    Super MURCer
    • Sep 1999
    • 7645

    #2
    There is an eazy fix for this, "Don't use IE"
    If there's artificial intelligence, there's bound to be some artificial stupidity.

    Jeremy Clarkson "806 brake horsepower..and that on that limp wrist faerie liquid the Americans call petrol, if you run it on the more explosive jungle juice we have in Europe you'd be getting 850 brake horsepower..."

    Comment

    • The PIT
      Super MURCer
      • Aug 1999
      • 11901

      #3
      Fix coming this Tuesday I believe. Until they find the next hole
      Chief Lemon Buyer no more Linux sucks but not as much
      Weather nut and sad git.

      My Weather Page

      Comment

      • Elie
        MURC Writer
        • Aug 1999
        • 4420

        #4
        It's interesting how all or most of the Windows bugs are directly related to IE

        Comment

        Working...