• On GameSpot: Wii Fit tells 10-year-old she's fat
July 7, 2008 12:31 PM PDT

Microsoft probing ActiveX attacks targeting Access feature

Microsoft issued a security advisory on Monday warning about targeted attacks being launched that exploit a hole in the ActiveX control for the Snapshot Viewer in the Microsoft Access database management system.

Basically, an attacker would have to lure a victim, via a link in an e-mail or IM for instance, to a specially crafted Web page that could exploit the security hole to allow remote code execution. This would provide the attacker with as much access to and rights on the computer as the logged-in user has.

The vulnerability only affects the ActiveX control for the Snapshot Viewer for Microsoft Office Access 2000, 2002 and 2003.

The ActiveX control, which allows a user to view an Access report snapshot without having the standard or run-time versions of Microsoft Office Access, ships with the standalone Snapshot Viewer and with all supported versions of Microsoft Office Access except for Microsoft Office Access 2007.

By default, Internet Explorer on Windows Server 2003 and Windows Server 2008 run in a restricted mode known as Enhanced Security Configuration that sets the security level for the Internet zone to "high." This is a mitigating factor for Web sites that a user has not added to the Internet Explorer Trusted sites zone, according to Bill Sisk, security response communications manager for Microsoft.

In addition, a security feature in Internet Explorer can be set to prevent ActiveX controls from being loaded by the IE HTML-rendering engine, the advisory says.

Microsoft suggests that users adopt a workaround, such as configuring IE to disable Active Scripting or to prompt before running it, or setting Internet and local intranet security zone settings to "high" to prompt before running ActiveX Controls and Active Scripting.

Eventually, Microsoft may provide a security update for the vulnerability, according to the frequently-asked-questions section of the advisory.

"While the attack appears to be targeted, and not widespread, we are monitoring the issue and are working with our MSRA (Microsoft Security Response Alliance) partners to help protect customers," Sisk says.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 and previously covered search, online advertising, and portals. E-mail Elinor.
Recent posts from News Blog
Navy charters kite-powered cargo ship to deliver equipment
EA Mobile, Eidos Interactive sign agreement
Sprint first to offer HTC Touch Pro
Flipping out: RIM BlackBerry Pearl Flip 8220 debuts
Sprint HTC Touch Diamond outed early
Add a Comment (Log in or register) 7 comments
by Penguinisto July 7, 2008 4:23 PM PDT
...now all it would take is to hijack an existing website to add a redirect. Gah... glad I don't use MSFT products for anything I deem important.
Reply to this comment View reply
by The_Decider July 8, 2008 12:26 AM PDT
ActiveX security holes are the easiest thing in the world to write exploits for. MS needs to get a clue and ditch this terrible API that is nothing more then a performance and security nightmare that was only created to enforce lock in. Oh, and Vegetable Head, you need to get some technical knowledge.
Reply to this comment
by Guru Master July 8, 2008 3:37 AM PDT
A) Reporting on any specifics of security related issues is just plain bad journalism.
B) 'Targeted' attack means that people have spent a great deal of effort to create the code necessary to result in the vulnerabilty.
C) Even people with online pseudos that include 'Penguin' (Linux nerds) openly admit they use MSFT products, "MSFT products for anything I deem important" - what is important?
D) A socially engineeed attack is useless with proper controls in place and user training. This will only likely affect the small company who has hired a few dolts and lacks an enforced security model.
E) All software can be targeted. Just happens more people use and know MS products.
F) If you compared usage of Linux related products to the total vulnerabilities found (vs. other products), you would have a lop-sided number showing how truly lacking those products are in overall security.
Reply to this comment
by mowito July 9, 2008 5:08 AM PDT
pls i really need to download active x
Reply to this comment
by JandNLarson July 9, 2008 11:46 AM PDT
I concur with several other posters:
1. Whose bright idea was it to publicize a not-dealt-with security hole?
2. Why is Microsoft still running this outdated security nightmare?
3. The entire OS and program-software industry needs to shore up security without making the programs unusable!
Reply to this comment
by caw1995 July 15, 2008 2:09 PM PDT
I totally agree with JandNLarson.
Reply to this comment
Powered by Jive Software
advertisement
Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

News Blog topics

Featured blogs

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right