Skip to main content

Microsoft Warns of Zero-Day ActiveX Vulnerability in Windows XP

Microsoft Warns of Zero-Day ActiveX Vulnerability in Windows XP

Microsoft has issued a security advisory warning Windows XP users to take immediate steps to protect themselves from an ActiveX security vulnerability that’s already being exploited, particularly in Asia. The problem only impacts Windows XP—which, unfortunately, happens to be one of the most widely-used operating systems on the planet—and would let attackers run arbitrary code as if they were the currently logged-in user. Windows Vista and Windows Server 2008 are not impacted, nor is Windows 2000 SP4. Microsoft is working on a patch; in the meantime, Microsoft is urging users to disable the Microsoft Video ActiveX control from running in Internet Explorer.

The workaround sets a “kill bit” for Microsoft’s Video ActiveX control in the Windows Registry which will prevent Internet Explorer from loading the control. Although it doesn’t eliminate the vulnerability from the system, it does prevent malicious sites from being able to exploit the problem. Microsoft says there are no “by design” uses for the Video ActiveX control in Internet Explorer, so disabling the control shouldn’t have any significant ramifications for users. Microsoft is even recommending Windows Vista and Windows Server 2008 users set the kill bits just in case.

Microsoft has not given a date for when it expects a security patch to be available. The company’s next “Patch Tuesday” update is July 14; a fix might be included in that update, or could be issued separately.

The code for the ActiveX exploit has already been published on a number of Chinese sites.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Update Chrome now to avoid this major zero-day exploit
Google Chrome open with several tabs.

The Google Chrome browser has been hit by its first zero-day attack of 2023, and Google has begun rolling out an emergency update as of today to address the exploit.

Google detailed on its Chrome Release blog that it is aware that an exploit for CVE-2023-2033 exists in the wild. It has likely been circulating since the beginning of the year, according to Bleeping Computer.

Read more
Microsoft warns that relying on Internet Explorer may cause disruptions
windows 10 june update will kill internet explorer for good poznan  pol may 1 2021 laptop computer displaying logo

Microsoft has announced it will continue end-of-life updates in 2023 for its former browser, Internet Explorer, for older Windows versions.

Despite having ceased IE support on the current Windows 11 operating system version on June 15, Microsoft still allowed the legacy browser to function on many older versions, including Windows 10 Home, Pro, Enterprise, Edu, and IoT.

Read more
It’s not just you: Microsoft confirms Windows 11 is having gaming issues
Acer Predator Orion 7000 sitting on a table.

Microsoft has confirmed that the latest update to Windows 11 is causing performance issues in some games, along with a host of other problems. Stuttering might be noticeable in some apps as well.

Microsoft has put a hold on its Windows 11 22H2 update on devices affected by this issue; however, it is still possible to install the update manually. If you haven’t updated yet, it’s best to wait until you get a notification that an update is available.

Read more