Attacks Against Unpatched Microsoft Bug Multiply 122
CWmike writes "Attacks exploiting the latest Microsoft vulnerability are quickly ramping up in quantity and intensity, several security companies warned today as they rang alarms about the developing threat. Symantec, Sunbelt Software, and SANS' Internet Storm Center bumped up their warnings yesterday after Microsoft announced that attackers were exploiting a bug in an ActiveX control used by IE to display Excel spreadsheets. There is no patch for the vulnerability; Microsoft didn't release one in today's Patch Tuesday. A temporary fix that sets the 'kill bits' of the ActiveX control is available, but experts believe it's likely most users won't take advantage of the protection. Symantec raised its ThreatCon ranking to the second of four steps. "We're seeing it exploited, but currently on a limited scale," said Symantec's Ben Greenbaum. Sunbelt also bumped up its ranking, to high." Firefox users can't be too complacent; Secunia is warning of a 0-day in version 3.5.
Firefox 3.5? (Score:5, Funny)
Firefox users can't be too complacent; Secunia is warning of a 0-day in version 3.5.
Well, I guess I'm safe. At my workplace, my Redhat 9 installation is incapable of running any version newer than Firefox 2.0.0.20.
Microsoft is crap (Score:0, Funny)
Mod me up, cause I talked bad about Microsoft. It's the Slashdot way and you must stick with the Slashdot norms otherwise you'll look like a complete asshole.
It's about time... (Score:2, Funny)
Only 9 posts? (Score:5, Funny)
Active X again? (Score:4, Funny)
With the number of ActiveX related security issues you would have thought they would simply drop it or at least sandbox it?
More than multiplying, I'm afraid (Score:3, Funny)
Re:Microsoft is crap (Score:3, Funny)
Re:Ohh noes.... (Score:5, Funny)
Without an unsandboxed version of the win32 api, which is what ActiveX is, they would be unable to deny the ability to use the internet to those without a recent version of windows and office.
My head didn't stay unexploded while I wasn't unreading this unstatement.
Re:Firefox 3.5? (Score:2, Funny)
It's the same as the cool kid in highschool. Popularity also means more people will hate him, or exploit his keyless entry, or the bug in his active x controllers.
Re:Ohh noes.... (Score:3, Funny)
I'm a little more militant in my opinion of ActiveX.
Dumbest idea EVER. Microsoft has tossed more money down this sinkhole of a technology trying to fill the hole. People, Companies and governments have tossed even more down the same hole fixing issues that directly arise from some ActiveX bug.
How much further along would Microsoft have been along if they had just passed over this DUMB marketing idea anyway. ( It had to come from marketing, it must have, really who else could be this dumb. )
What it's been a decade of disaster when it comes to ActiveX issues.
Guys it's a bad idea. It's lame, take it out back and shoot it. Just say out loud, "We are sorry, this will never be in another one of our products after this point."
However it has made a lot of my product buying decisions over the years a lot easier. I ask the sales nerd. "Does this product make use of ActiveX in any way? I mean even as an optional addon?". If I get the reply, "Yes", or "We are building ActiveX into the next version.". I simple end the meeting and escort them to the door and give them a complimentary donut. ( I'm getting a bit like that when the caffeinated hyper English sales guy screams, web2.0 AJAX twitter in my face when he's only talking about the product packaging. )
Back to ActiveX. Again I say, DUMBEST IDEA EVER!
Sorry I take that back. Sub-Prime Mortgages, that's the dumbest idea ever. We'll give you money at a loss, not really check your credit, and expect you to be able to repay at an insane rate in 3-5 years time. Now that's a DUMB idea.
Re:It's about time... (Score:3, Funny)
Yo dawg, I heard you liked ActiveX, so I put some Excel in your Excel so you could get exploited while you were getting exploited.