Microsoft knew about IE bug since last year
By Asavin Wattanajantra,
Microsoft knew about an ActiveX control flaw that has now left Internet Explorer users vulnerable to attack, since last spring.
Mike Reavey, director of the Microsoft Security Response Centre, said in its blog that it received a report from the IBM ISS X-Force last year.
In an investigation it was confirmed that the ActiveX control shipping with Windows had an exploitable vulnerability.
The company didn’t issue an advisory until this week, when reports first surfaced that hackers were taking advantage of the vulnerability to target Internet Explorer users.
Engineering teams believed that the best approach was to completely remove the ActiveX control from Internet Explorer, but it took some time for Microsoft to properly evaluate what this could do.
Reavey said that when disabling or removing functionality, Microsoft had to engage in more research and testing than usual. This ensured that it could take the step and not cause more harm than good by inadvertently ‘breaking’ applications.
He said: “For something like this, we have to ensure not only our applications but also major third-party applications are not hurt by this.
“Otherwise, if out update ‘breaks’ a major application, customers won’t deploy the update but the bad guys will have information about the vulnerability they can use to attack it,” Reavey added.
The Microsoft statement came as it revealed that at next week’s Patch Tuesday it would release a total of six security bulletins with three critical updates for Windows.
The ActiveX flaw will be fixed, as well as an earlier vulnerability that affected Microsoft DirectX.
You may also like...
advertisement
Latest Security Features
Q&A: The ID card commissioner talks cards and controversy
We spoke to ID card commissioner Sir John Pilling about his thoughts on the identity scheme and why we might all think he's a bit of prat down the line.
- So you've been hacked, now what?
- The problems facing Internet Explorer
- Year in Review: 2009 in your words
- Top 10 security predictions for 2010
- Year in Review: Top tech stories of 2009
- The worst IT disasters of 2009
- Five free security software suites
- How to stay safe shopping online
- Is it time to switch to IPv6?
Latest Security Reviews
WatchGuard XCS-770 review
Rating: ![]()
advertisement
Most popular
- Google Nexus One review: A week with the superphone
- Conservatives promise 100Mbps in tech manifesto
- Google Nexus One UK launch confirmed for next month
- HTC Legend review
- Public internet access: who is responsible?
- Head to Head: Google Nexus One vs Apple iPhone 3GS
- BBC slammed over Facebook training
- Samsung N150 review
- Virgin to run fibre broadband over telegraph poles
- GCHQ?s ?cavalier attitude? leads to 35 lost laptops
Latest News Videos in Security
Video: Why security is everybody's responsibility
Rik Ferguson, senior security advisor at Trend Micro says it's up to all of us to make security work.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






