Quantcast
0
5
Tuesday, July 08, 2008 11:49 AM PDT

Watch Out for an IE Zero-Day Attack

Microsoft yesterday warned of a new attack underway against a flaw in the ActiveX control for the Snapshot Viewer for Microsoft Access, used by IE. There is not yet any patch available for the zero-day security hole, and the attacks likely focus on business targets.

In its security advisory, Redmond says the vulnerable control installs with "all supported versions of Microsoft Office Access except for Microsoft Office Access 2007. The ActiveX control is also shipped with the standalone Snapshot Viewer." A poisoned Web page that exploits the hole could surreptitiously download malware to a victim PC.

"Active, targeted attacks" are underway on a relatively small scale, according to the advisory.  Targeted attacks typically involve more careful planning and crafting, and may use a victim's name and title in a socially engineered e-mail with a link to a malicious site, for example. I usually only see targeted attacks against businesses, which fits given the vulnerability in Microsoft Access.  So watch out for this while you're at work.

The US-CERT vulnerability report doesn't inspire hope: "We are currently unaware of a practical solution to this problem." You can set what's known as a kill bit for this particular ActiveX control to prevent it from running in IE, but doing so could prevent you from viewing Access report snapshots, and it involves mucking with the Windows Registry. See this Microsoft Support Page for kill bit instructions (the CLSID is in the security advisory).

The US-CERT report also says that IE 7's ActiveX opt-in feature should help mitigate the vulnerability, which the Microsoft advisory surprisingly doesn't mention. That should mean that you'd get a prompt before running the control on a poisoned page, and would have a chance to stop it before it attacked your computer.

If you have the choice, it may be a good idea to use Firefox until this hole is fixed.  And if you're still on IE 6 at work, hammer on your IT to get you upgraded.  Every security expert I talk to says you're basically asking for it if you surf the web with the outdated browser. If there's a particular in-house app that only works with IE 6, then use Firefox as your default Web browser, and only fire up IE 6 for that old app.

Community Comments
News
More
Featured Resources

Premier Content From Our Sponsors

  • HP Ink Center
    HP Ink Center You don't need a big budget to produce high quality marketing materials. Click here for more info...
  • CDW Virtualization Center
    CDW Virtualization Center What is Virtualization and how can it help you save money? Click here for more info...
Featured Whitepapers

White papers, case studies and product info from top brands

  • Applications, Virtualization and Devices: Taking Back Control Employees installing legitimate but unauthorized applications, are a real and growing threat to business security and productivity. Removable storage media and wireless protocols make the challenge of securing data even more complex. This paper expl...
  • The Evolution of IT Operations Effective IT operations are the baseline for successful businesses. Effective IT service delivery is the baseline for effective IT operations. Delivering high-quality services requires well-designed and highly automated IT operations processes in lo...
Featured Webcasts

Watch webcast presentations and videos from industry thought leaders on today's most important business and technology topics. For free.