ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Microsoft patches ActiveX flaw

July's Patch Tuesday sees Microsoft release six patches for nine vulnerabilities.

By Nicole Kobie, 15 Jul 2009 at 10:59

patched computer

Microsoft has released six fixes for nine flaws, including three critical ones in Windows.

The three Windows patches fix three DirectShow flaws, two for the OpenType Font engine, and one major one in the ActiveX control in Internet Explorer.

"All three of those also have an exploitability Index rating of “1” which means that we believe that consistent exploit code in the wild is highly likely within the first 30 days," said Microsoft security researcher Jerry Bryant in a blog post, noting two are already under active attack.

“We’re glad to see Microsoft addressed the zero-day vulnerability in its video ActiveX control, even if it is not in the form of an actual patch,” said Ben Greenbaum, senior research manager, Symantec Security Response.

“The flaw was already being exploited in Asia. There was potential for this to become a bigger problem for users if left unaddressed by Microsoft," he added. "In the meantime, the update that disables the vulnerable controls should help.”

The other three bulletins are rated important, despite also being set for exploit. They affect Publisher, ISA Server and Virtual PC Server. A flaw was also found in Virtual PC, but it is less likely to be immediately exploited.

The zero-day flaw in Microsoft Officethat could leave users open to attack, announced on Monday, remains unpatched by this latest Patch Tuesday cycle. In the meantime, Microsoft has produced a workaround.

Email to a friend

Print this page

< Previous   Security : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement