By George Norman - Software News Editor
Added on 14 Jul 2009(112 Views)
The week started with Microsoft announcing to the world that yet another ActiveX vulnerability has been uncovered: this time the vulnerability affects Microsoft Office Web Components and may allow the person with malicious intent that exploits it to take control of the targeted machine. And if the remote code execution was not enough, Microsoft said that it is aware of attacks exploiting this Office Web Components Spreadsheet ActiveX control (OWC 10 and OWC11) vulnerability.

I said “yet another ActiveX vulnerability” above because about a week ago the company announced it is aware of a Microsoft Video ActiveX Control vulnerability that when exploited by a person with malicious intent would give the attacker the same user rights as the local user. All you have to do to get owned is use Internet Explorer and visit a malicious web site. This vulnerability alongside many others will be addressed with the July 2009 Patch Tuesday update.


Group Manager with Microsoft’s Security Response Communications (MRSC) team, Dave Forstrom, comments: “We have just posted Microsoft Security Advisory 973472, which highlights a vulnerability in Microsoft Office Web Components. Specifically, the vulnerability exists in the Spreadsheet ActiveX control and while we’ve only seen limited attacks, if exploited successfully, an attacker could gain the same user rights as the local user. We’re currently investigating the issue as part of our Software Security Incident Response Process (SSIRP) and working to develop a security update. This update will be released once it reaches an appropriate level of quality for broad distribution.”

Affected products include:
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 3
Microsoft Office XP Web Components Service Pack 3
Microsoft Office 2003 Web Components Service Pack 3
Microsoft Office 2003 Web Components for the 2007 Microsoft Office system Service Pack 1
Microsoft Internet Security and Acceleration Server 2004 Standard Edition Service Pack 3
Microsoft Internet Security and Acceleration Server 2004 Enterprise Edition Service Pack 3
Microsoft Internet Security and Acceleration Server 2006
Microsoft Internet Security and Acceleration Server 2006 Supportability Update
Microsoft Internet Security and Acceleration Server 2006 Service Pack 1
Microsoft Office Small Business Accounting 2006

What does the use have to do to get become compromised? The attack vector is quite simple: all the user has to do is visit a specially crafted web page to get owned.

Microsoft’s Security Advisory 973472 is available here. It presents detailed info about the vulnerability and a workaround for the security hole.
Alternatively you can use Microsoft Fix It to automatically apply the workaround – details in the Microsoft Knowledge Base Article 973472 here.





Don't forget to:

RSS


Tags: Microsoft, ActiveX, Vulnerability, Security, Microsoft Office Web Components

Link to this article:



Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Software News
Chromium OS Goes Open-Source
This summer Google let the world know that it is working on a new operating system meant for the user that spends most of his time online. The operating system – aptly named Chrome OS because it is a natural extension...
20 Nov 2009
Office 2010 Beta Downloads Available to the Public
Earlier this week Redmond-based software giant Microsoft announced that Office 2010 became available for download as a Beta. The catch was that only ...
20 Nov 2009
Mozilla Releases: Firefox 3.6 Beta 3
The development process of the Firefox 3.6 browser is moving along rapidly. The first Beta version was released at the start of the month; Beta 2 was released about two weeks after Beta 1. About a week has passed since...
20 Nov 2009
New Labs Feature for Gmail: Green Robot!
The software developers at Google have announced the release of a new Gmail Labs offering called Green Robot! This new offering is meant to improve the Gmail Chat user experience by letting the ...
20 Nov 2009
Opera Mobile 10 Beta for Windows Mobile Is Out Also
Opera Software, the company that we all know for making the innovative and feature rich Opera web browser, has released Opera Mobile 10 Beta for Windows Mobile-powered devices. This release follows in the...
19 Nov 2009
Beta Testing is Over, Stable Version of Trillian for iPhone Released
The focus so far has been on desktop version of this multiprotocol instant messaging software application, Trillian Astra (version 4.1). Today is time to switch focus away from the desktop version and onto something a bit more...
19 Nov 2009
Recommended Tools

Top Downloads