Microsoft posts work-around for IE flaw

Microsoft released on Friday a work-around for an Internet Explorer vulnerability that has left Windows users open to attacks for almost nine months.

The flaw, in an ActiveX scripting component, gained notoriety last month when it became the mechanism used by a network of compromised Web sites to install a malicious program on victims' computers. Microsoft has decided to plug the hole by turning off the ability for the ActiveX component to write to the operating system. The software giant published the work-around on its Web site and directed customers to use its Windows update service to download the patch.

Though Microsoft intends the change to become a standard configuration for Windows, the software giant is working on a more comprehensive solution, said Stephen Toulouse, security program manager for Microsoft's security response center.

"It is a permanent change, but it is an interim step--we are still in the middle of our investigation," he said. "We have taken a look at the functionality in the product and seen that that functionality is really being used by attackers."

The change fixes a problem that allowed several compromised Web sites to infect visitors' PCs with a Trojan horse program, known as Download.Ject or JS.Scob.Trojan. The program would record the keystrokes and send them to an overseas e-mail address. That Internet Explorer security issue and several others lead some security experts to suggest that users should consider alternative browsers.

Microsoft's configuration change blocks the ability of the ADODB.screen ActiveX component to write to the PC's hard drive. ActiveX, which adds interactivity to Web sites viewed with Internet Explorer, has long been thought to have security issues.

This particular vulnerability has been known about for more than 9 months, said David Endler, director of incident response for security company Tipping Point.

"Though written configuration hardening instructions have been available online for a while, it's nice to finally see this particular security tweak in Internet Explorer distributed to the masses, even if it's long overdue," he said.

Microsoft continues to study this issue and expects to release a more comprehensive patch. Moreover, the company is readying a major security update for Windows XP, known as Service Pack 2, that should be out later this year.

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 2 comments

  1. I have the ActiveX disable on the system for two years now and everytime I read about this activex problem ya have too wonder what else is wrong with inclusion of a program's that is brought out by MicroSuck , IE is nothing more than a bug ridden program Anonymous -- 07/07/04

    I have the ActiveX disable on the system for two years now and everytime I read about this activex problem ya have too wonder what else is wrong with inclusion of a program's that is brought out by MicroSuck , IE is nothing more than a bug ridden program that I have disable too for sometime now , I remmeber when the ActiveX first came , that reading some articles about the con's and how unsecure the system became because of activex , and that the program made the system virtually unsecuritable from a security point of view .One wonder when will MS every get it right with security issues.

  2. This is a technology news site. Please include relevant hyperlinks within the stories. In this story a direct link to the MS site entry would have added value to your article. Anonymous -- 08/07/04

    This is a technology news site.

    Please include relevant hyperlinks within the stories.

    In this story a direct link to the MS site entry would have added value to your article.

Add your opinion


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue Telstra's BT coat doesn't fit
    The vision of the future BT portrayed this week at an Australian conference was so far removed from how Telstra's David Quilty has described the British telco that I wonder if they were talking about the same UK.
  • Array Australian security: the lucky country
    Does anyone seriously believe that Australian businesses and government agencies manage security any better than the US or UK?
  • Array Storage infrastructure on the tender track
    For a large-scale storage project, it's not uncommon to go out to tender for the best deal — but when was the last time you had to put together a tender for a document management room?
  • More blogs »

Tags

Back to top

Featured