Tuesday 7 July 2009

Microsoft Security Advisory For Windows XP and Windows Server 2003 Users

If you are running Windows XP or Windows Server 2003 then you will need to take heed of a new Security Advisory being issued by Microsoft. The vulnerability is “in Microsoft Video ActiveX Control. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. When using Internet Explorer, code execution is remote and may not require any user intervention.”

Microsoft are saying that:

For Windows XP and Windows Server 2003 customers, Microsoft is recommending removing support for this ActiveX Control within Internet Explorer using all the Class Identifiers listed in the Workaround section. Though unaffected by this vulnerability, Microsoft is recommending that Windows Vista and Windows Server 2008 customers remove support for this ActiveX Control within Internet Explorer using the same Class Identifiers as a defense-in-depth measure.”

As you can see from the above quote Microsoft are also recommending that Vista and Windows Server 2008 users also do this.

There is an automated fix for this available from Microsoft, which makes things easier for you.

You can get the Microsoft fix at the following link:

“Microsoft Security Advisory: Vulnerability in Microsoft Video ActiveX control could allow remote code execution

For those that want to read more go to the following link:

Microsoft Security Advisory (972890) Vulnerability in Microsoft Video ActiveX Control Could Allow Remote Code Execution

No comments: