Advertisement
Promo

Security threats Toolkit

Microsoft warns of ActiveX attacks targeting Access

Elinor Mills CNET News

Published: 08 Jul 2008 08:29 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft issued a security advisory on Monday warning about targeted attacks that exploit a hole in the ActiveX control for the Snapshot Viewer in the Microsoft Access database-management system.

An attacker would have to lure a victim, via a link in an email for instance, to a specially crafted web page that could exploit the security hole to allow remote code execution. This would provide the attacker with as much access to and rights on the computer as the logged-in user has.

The vulnerability only affects the ActiveX control for the Snapshot Viewer for Microsoft Office Access 2000, 2002 and 2003.

The ActiveX control, which allows a user to view an Access report snapshot without having the standard or run-time versions of Microsoft Office Access, ships with the standalone Snapshot Viewer and with all supported versions of Microsoft Office Access except for Microsoft Office Access 2007.

By default, Internet Explorer (IE) on Windows Server 2003 and Windows Server 2008 runs in a restricted mode known as Enhanced Security Configuration that sets the security level for the internet zone to 'high'. This is a mitigating factor for websites that a user has not added to the Internet Explorer Trusted sites zone, according to Bill Sisk, security response communications manager for Microsoft.

Read this

Comment
Comment: It's not the Gates, it's the bars

To pay so much attention to Bill Gates's retirement is missing the point; it is neither Gates nor Microsoft that really matter, says the Free Software Foundation's Richard Stallman

Read more +

In addition, a security feature in IE can be set to prevent ActiveX controls from being loaded by the IE HTML-rendering engine, the advisory states.

Microsoft suggested that users adopt a workaround, such as configuring IE to disable Active Scripting or to prompt before running it, or setting internet and local intranet security zone settings to 'high', to prompt before running ActiveX controls and Active Scripting.

Eventually, Microsoft may provide a security update for the vulnerability, according to the frequently-asked-questions section of the advisory.

"While the attack appears to be targeted, and not widespread, we are monitoring the issue and are working with our MSRA [Microsoft Security Response Alliance] partners to help protect customers," Sisk said.

Credit: Microsoft probing ActiveX attacks targeting Access feature from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

1 comment

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters