Microsoft knew about IE bug since last year
By Asavin Wattanajantra,
Microsoft knew about an ActiveX control flaw that has now left Internet Explorer users vulnerable to attack, since last spring.
Mike Reavey, director of the Microsoft Security Response Centre, said in its blog that it received a report from the IBM ISS X-Force last year.
In an investigation it was confirmed that the ActiveX control shipping with Windows had an exploitable vulnerability.
The company didn’t issue an advisory until this week, when reports first surfaced that hackers were taking advantage of the vulnerability to target Internet Explorer users.
Engineering teams believed that the best approach was to completely remove the ActiveX control from Internet Explorer, but it took some time for Microsoft to properly evaluate what this could do.
Reavey said that when disabling or removing functionality, Microsoft had to engage in more research and testing than usual. This ensured that it could take the step and not cause more harm than good by inadvertently ‘breaking’ applications.
He said: “For something like this, we have to ensure not only our applications but also major third-party applications are not hurt by this.
“Otherwise, if out update ‘breaks’ a major application, customers won’t deploy the update but the bad guys will have information about the vulnerability they can use to attack it,” Reavey added.
The Microsoft statement came as it revealed that at next week’s Patch Tuesday it would release a total of six security bulletins with three critical updates for Windows.
The ActiveX flaw will be fixed, as well as an earlier vulnerability that affected Microsoft DirectX.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Yahoo CEO resigns after CV debacle
- Apple iPad 3 vs iPad 2 head-to-head review
- Macs under attack?
- HP to bring indestructible plastic displays and Memristor storage to market
- Fusion-IO share price soars on back of Dell merger rumours
- Android users warned of fake app store malware risk
- Dell PowerEdge R820 review
- Is BT the key to broadband Britain?
- What is your password worth?
- Police quiz UK teen over TeamPoison attacks
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.




