Skip to main content

Microsoft Warns of Zero-Day ActiveX Vulnerability in Windows XP

Microsoft Warns of Zero-Day ActiveX Vulnerability in Windows XP

Microsoft has issued a security advisory warning Windows XP users to take immediate steps to protect themselves from an ActiveX security vulnerability that’s already being exploited, particularly in Asia. The problem only impacts Windows XP—which, unfortunately, happens to be one of the most widely-used operating systems on the planet—and would let attackers run arbitrary code as if they were the currently logged-in user. Windows Vista and Windows Server 2008 are not impacted, nor is Windows 2000 SP4. Microsoft is working on a patch; in the meantime, Microsoft is urging users to disable the Microsoft Video ActiveX control from running in Internet Explorer.

The workaround sets a “kill bit” for Microsoft’s Video ActiveX control in the Windows Registry which will prevent Internet Explorer from loading the control. Although it doesn’t eliminate the vulnerability from the system, it does prevent malicious sites from being able to exploit the problem. Microsoft says there are no “by design” uses for the Video ActiveX control in Internet Explorer, so disabling the control shouldn’t have any significant ramifications for users. Microsoft is even recommending Windows Vista and Windows Server 2008 users set the kill bits just in case.

Microsoft has not given a date for when it expects a security patch to be available. The company’s next “Patch Tuesday” update is July 14; a fix might be included in that update, or could be issued separately.

The code for the ActiveX exploit has already been published on a number of Chinese sites.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Microsoft is removing a Windows app that’s almost 30 years old
Computer user touching on Microsoft Word icon to open the program.

Microsoft is saying goodbye to WordPad, its long-supported rich text application, which will no longer receive updates as of September 1.

The brand recently announced that the app is now among its list of deprecated Windows features. Microsoft explained the difference between deprecation and removal, noting that the former is when a feature is at the end of its life cycle and is no longer in active development, and the latter is when a feature is removed after having been deprecated.

Read more
Microsoft leaked a tool that unlocks all of Windows 11’s hidden features
Windows 11 device sitting on a stool.

 

A recent leak of a Microsoft internal tool will allow enthusiasts to gain access to hidden Windows 11 features in the same way Microsoft engineers test unreleased software, according to Windows Central.

Read more
Microsoft Build 2023: the biggest announcements in AI, Windows, and more
microsoft build 2021 everything announced nadella 1

Microsoft's annual developer's conference has arrived, and a slew of big announcements have already been unveiled. AI is, obviously, the big theme of the event and continues to be top-of-radar for Microsoft and the entire tech community.

But there are also some big announcements for Windows, the Edge browser, Teams, and more.
AI comes to Windows

Read more