1. Home
  2. Computing & Technology
  3. Web Browsers
photo of Scott Orgera
Scott's Web Browsers Blog

By Scott Orgera, About.com Guide to Web Browsers

Microsoft Cautions Users About ActiveX Vulnerability

Wednesday July 9, 2008

A vulnerability in the ActiveX control for Microsoft's Snapshot Viewer can lead to remote code execution. According to a security advisory released by Microsoft earlier this week, successful exploitation of this vulnerability could provide an attacker with the same user rights on a victim's machine as the logged-on user. Someone operating with administrative rights would be in great danger at this point.

The company is currently investigating active, targeted attacks which are being initiated by tricking users into viewing specially crafted Web content through the Internet Explorer browser. You may be at risk if you have any version of Microsoft Office Access other than Access 2007 installed, or if you have installed the standalone version of Snapshot Viewer.

Until the vulnerability itself is fixed, Microsoft has issued a few workarounds which help block known attack vectors. Each of the workarounds involve the IE browser and have their own unique level of impact.

(Photo © devon - #691016/stockxpert)

Comments

No comments yet. Leave a Comment

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Explore Web Browsers
About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >

  1. Home
  2. Computing & Technology
  3. Web Browsers

©2009 About.com, a part of The New York Times Company.

All rights reserved.