Help - Search - Members - Calendar
Full Version: Microsoft Xmlhttp Activex Control Code Execution Vulnerability
TotalChoice Hosting Family Forums > TotalChoice Hosting General Support > Security Discussions > Software/Scripts/Other Alerts
TCH-Thomas
Secunia reports this as extremely critical.

Read more here at: http://secunia.com/advisories/22687/

Description:
A vulnerability has been reported in Microsoft XML Core Services, which can be exploited by malicious people to compromise a users system.

The vulnerability is caused due to an unspecified error in the XMLHTTP 4.0 ActiveX Control.

Successful exploitation allows execution of arbitrary code when a user e.g. visits a malicious website using Internet Explorer.

NOTE: The vulnerability is already being actively exploited.

Solution:
Microsoft has recommended various workarounds including setting the kill-bit for the affected ActiveX control (see the vendor's advisory for details).
TCH-Bruce
Thanks Thomas

Firefox is a better choice every day wink.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.