1. Home
  2. Computing & Technology
  3. Antivirus Software
photo of Mary Landesman
Mary's Antivirus Software Blog

By Mary Landesman, About.com Guide to Antivirus Software since 2000

Microsoft Zero Day Cause for Concern

Wednesday July 8, 2009

An unpatched buffer overflow vulnerability in an ActiveX control used by Microsoft DirectShow is being actively exploited in-the-wild. A large number of websites in China have been compromised and are being used to distribute the exploit. Malicious ads targeting game sites are also employing the zero day exploit. The exact malware that results depends on the attack vector encountered, but thus far consist of a range of data theft and password-stealing trojans.

According to Shavlik Technology, the problem-causing ActiveX control "doesn’t serve any purpose within Internet Explorer" - which makes it even more alarming that Microsoft has known about the problem for over a year and neglected to fix it.

To workaround the problem while awaiting a patch, Microsoft recommends setting a kill-bit for the offending ActiveX control - a protection method that can lead to application problems and has a not-insignificant failure rate (as in, it may not protect you).

My recommendation: switch to Firefox with NoScript. Now.

Comments

No comments yet. Leave a Comment

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Discuss
Community Forum
Explore Antivirus Software
About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >

  1. Home
  2. Computing & Technology
  3. Antivirus Software

©2009 About.com, a part of The New York Times Company.

All rights reserved.