ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Attackers target zero-day Windows flaw

Greg Sandoval CNET News.com

Published: 07 Nov 2006 09:48 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An "extremely critical" vulnerability has been discovered in Microsoft's XML Core Services, according to several security companies.

The vulnerability, which affects only systems running Internet Explorer, is caused by an unspecified error in the XMLHTTP 4.0 ActiveX Control and could be used to seize control of an affected system, according to an advisory from Secunia, a security company based in Denmark.

IBM-owned ISS X-Force detailed on its site the kind of damage that could be caused by the vulnerability.

"This could lead to loss of confidential information, disruption of business, or further compromise," according to the security company.

For the vulnerability to be exploited, a user would have to visit a malicious website, Secunia said.

Microsoft acknowledged that the bug is already being exploited, in a note posted to the company's site.

"We are aware of limited attacks that are attempting to use the reported vulnerability," Microsoft said.

Some of the software that may be affected includes Windows 2000, Windows XP Service Pack 2 and Windows Server 2003.

People running Windows Server 2003 and 2003 Service Pack 1 in the default configuration with the Enhanced Security Configuration turned on aren't affected, Microsoft said.

Microsoft will determine, based on "customer needs", whether to release a patch during the company's monthly release process or an "out-of-cycle security update", the company said.

Microsoft's next patch release day is 14 November.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
456 out of 519 people found this useful


Full Talkback thread

1 comment

  1. GoodBye Weekend? welshtroll

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Senior Computing Officer

Please request an application pack, quoting Ref & Job Title, via: www.plymouth.ac.uk/vacancies Email: jobs@plymouth.ac.uk Tel: 01752 588199 (24 hour ...

Configuration Manager - ClearCase- Tier 1 Bank (No Banking experience)

Huxley Associates are currently looking for a Senior Configuration Manager / Build Manager to join a Tier 1 Banking client in London. The department ...

Analyst Programmer (fixed term 24 months)

A full application pack can be obtained at www.lse.ac.uk/jobsatLSE If you cannot download the pack, email hr.recruit.support@lse.ac.uk or call 020 ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment