Sony Brings the Bling with Swarovski Photoframe

Microsoft Warns of Zero-Day ActiveX Vulnerability in Windows XP

Microsoft Warns of Zero-Day ActiveX Vulnerability in Windows XP

Microsoft is warning Windows XP users to take immediate action to protect themselves from an ActiveX security flaw that's already being exploited, particularly in Asia.

Microsoft has issued a security advisory warning Windows XP users to take immediate steps to protect themselves from an ActiveX security vulnerability that’s already being exploited, particularly in Asia. The problem only impacts Windows XP—which, unfortunately, happens to be one of the most widely-used operating systems on the planet—and would let attackers run arbitrary code as if they were the currently logged-in user. Windows Vista and Windows Server 2008 are not impacted, nor is Windows 2000 SP4. Microsoft is working on a patch; in the meantime, Microsoft is urging users to disable the Microsoft Video ActiveX control from running in Internet Explorer.

The workaround sets a “kill bit” for Microsoft’s Video ActiveX control in the Windows Registry which will prevent Internet Explorer from loading the control. Although it doesn’t eliminate the vulnerability from the system, it does prevent malicious sites from being able to exploit the problem. Microsoft says there are no “by design” uses for the Video ActiveX control in Internet Explorer, so disabling the control shouldn’t have any significant ramifications for users. Microsoft is even recommending Windows Vista and Windows Server 2008 users set the kill bits just in case.

Microsoft has not given a date for when it expects a security patch to be available. The company’s next “Patch Tuesday” update is July 14; a fix might be included in that update, or could be issued separately.

The code for the ActiveX exploit has already been published on a number of Chinese sites.

Related Posts

  • No Related Posts

Trackback URL: http://www.digitaltrends.com/computing/microsoft-warns-of-zero-day-activex-vulnerability-in-windows-xp/trackback/

blog comments powered by Disqus

Join The Digital Trends Community

DT RSS Feed

Everyone wants to be an insider, and you can be one too! Choose your poison: sign-up for our Newsletter, join us on Facebook, or follow us on Twitter. Do all three and you'll be swimming in the the latest news, reviews, videos and more gadget goodness!

DT Newsletter Sign-Up

Sign-up for the Digital Trends newsletter and find out about the latest contests, the hottest content, and the most popular videos. Let us keep you up-to-date!

Our Facebook

Become a DT soldier! Join us on Facebook and share the best news, guides, videos and other cool information directly with all your friends. Some might even thank you for it!

Join the thousands and follow the best of us on Facebook.

Twitter Us

Do you like information in small snippets? Then our Twitter feed is just for you. Follow Digital Trends and you'll be able to catch up daily on our latest content, or even interact directly with our team. Tweet Tweet!

Join the thousands and follow the best of us on Twitter.

That’s Right, Sign-up For Our Monthly Random Prize Drawings and You Could Be That Winner.