On TechRepublic: Why Android beats iPhone
BNET Business Network:
BNET
TechRepublic
ZDNet

November 6th, 2006

Microsoft XML parser zero-day vulnerability in the wild

Posted by George Ou @ 4:38 pm

Categories: Browsers, Security

Tags:

Microsoft is warning of a new critical vulnerability in its XML Core Services 4.0 that can be exploited as an ActiveX control in Internet Explorer (all versions) though it does not affect Windows Vista.  While the component isn't installed by Windows by default and the exploit seems to be unreliable, it is still a good idea to take the precautionary measures.  Users and IT departments can deploy a registry fix which sets the kill bit for this XML ActiveX control by using a .REG file shown in this advisory.

[Update: I had to remove the .REG text here because I can't get the backslash to show up here.  Please copy it from Microsoft's advisory]

This is the second zero-day ActiveX control exploit that surfaced last week.  The previous ActiveX control exploit affected a component in Microsoft Visual Studio 2005 but not too many people have that component installed and IE7 has that component disabled by default.  Microsoft has taken a defensive stance with Internet Explorer 7 by disabling 90% of the ActiveX controls by default.  However, this latest XML parser vulnerability is one of the remaining ActiveX controls enabled by default.

Users can disable ActiveX in Microsoft Internet Explorer permanently or use an alternate browser like Mozilla Firefox or Opera if they want to avoid these types of issues, but certain websites that use ActiveX controls will fail to function.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 89 Talkback(s)
Default
Do you not understand what 'by default' means? The fact that you
can change it later is irrelevant.

If something isn't installed by default, there's absolutely no way it
can be enabled... (Read the rest)
Posted by: jragosta Posted on: 11/10/06 You are currently: a Guest | | Terms of Use
What, no exclamation point?  Letophoro | 11/06/06
Get a life  georgeou | 11/06/06
Really?  jragosta | 11/06/06
Read a little closer  NonZealot | 11/06/06
Then why?  jragosta | 11/07/06
You are thick, aren't you?!  NonZealot | 11/07/06
Thick?  jragosta | 11/07/06
Can you provide evidence to that fact NonZealot?  Scrat | 11/07/06
Whoops, submitted too early!  Scrat | 11/07/06
Yes  NonZealot | 11/07/06
Sure  jragosta | 11/07/06
Oh, and jragosta...  NonZealot | 11/06/06
That wasn't just plain old Malicious code  georgeou | 11/06/06
Wrong again  jragosta | 11/07/06
You're hallucinating  jragosta | 11/07/06
Ahh, I forgive you for your ignorance then  NonZealot | 11/07/06
Come on, George  jragosta | 11/07/06
More differences  georgeou | 11/06/06
You forgot the other differences  Robert Crocker | 11/07/06
The usual  jragosta | 11/07/06
I said I didn't like HOST based AV  georgeou | 11/07/06
Here's your exclamation mark  georgeou | 11/06/06
Good Going George  D. T. Schmitz | 11/06/06
Oh but I committed the sin of not covering this on Sunday  georgeou | 11/06/06
Yeh I saw that  D. T. Schmitz | 11/06/06
Backslashes aren't your friend  NonZealot | 11/06/06
Ah, I didn't see that, thanks  georgeou | 11/06/06
Another Exploit from the MOKB project for Windows!!!!!!  sigma2 | 11/07/06
No security expert would consider privilege escalation super critical  georgeou | 11/07/06
Except..  jragosta | 11/07/06
WEEEEEE!!!!!!  NonZealot | 11/07/06
No  jragosta | 11/07/06
I'd say.. for once George has his ducks in a row...  ju1ce | 11/07/06
It was a worthless solution  georgeou | 11/07/06
I'm going to base that statement you just made...  ju1ce | 11/07/06
I'll explain it again  georgeou | 11/07/06
Hey George I read your blog...  ju1ce | 11/07/06
You still don't understand the issue at hand  georgeou | 11/07/06
BTW, I am not disputing that's how you turn off Internet Sharing  georgeou | 11/07/06
Okay...  ju1ce | 11/07/06
No, you're being silly  georgeou | 11/07/06
Contradicting yourself again  jragosta | 11/08/06
You confuse too easily  georgeou | 11/08/06
So, George  jragosta | 11/08/06
George, this is what I see  NonZealot | 11/08/06
No, you're not  jragosta | 11/08/06
Fling... SPLAT!!  NonZealot | 11/09/06
Default  jragosta | 11/10/06
.reg  D. T. Schmitz | 11/07/06
Hurray!  tic swayback | 11/07/06
You just don't get it  jragosta | 11/07/06
Easy answer  NonZealot | 11/07/06
Not a good reason  tic swayback | 11/07/06
I don't think different  NonZealot | 11/07/06
That was Close  Harry Bardal | 11/07/06
His money can't be that magic  tic swayback | 11/07/06
Speaking of which...  NonZealot | 11/07/06
I'm working hard at it today  tic swayback | 11/07/06
WAAAAAA!!!!!  NonZealot | 11/07/06
Oh, you'll get one for Xmas...  tic swayback | 11/07/06
Too bad nz  jragosta | 11/07/06
Hit and run harry?  NonZealot | 11/07/06
I guess you haven't  zkiwi | 11/07/06
zkiwi, you are the best!!  NonZealot | 11/07/06
So...  zkiwi | 11/07/06
It says a lot about you...  NonZealot | 11/07/06
You're on a roll NonZealot  georgeou | 11/07/06
Way to go, George  jragosta | 11/08/06
NonZealot is his own man  georgeou | 11/08/06
Doesn't answer the "deserve" question though  tic swayback | 11/07/06
Thanks for the link tic  NonZealot | 11/07/06
So, George  jragosta | 11/08/06
Sneak Preview  D. T. Schmitz | 11/07/06
Sneak Previews  jragosta | 11/07/06
I guess we have a bigger problem!!  NonZealot | 11/07/06
Lack of logical argument is noted  jragosta | 11/07/06
You need a quote or you are a liar  NonZealot | 11/07/06
Let's see if we can figure this out.  jragosta | 11/07/06
It sure is hilarious!!!  NonZealot | 11/07/06
OKAY!!!!  D. T. Schmitz | 11/07/06
Which George are you referring to?  jragosta | 11/08/06
Issues  D. T. Schmitz | 11/08/06
Inherent security  jragosta | 11/07/06
HILARIOUS!!!  NonZealot | 11/07/06
I see it  Rick_K | 11/07/06
I see....  jragosta | 11/07/06
Hmm, that's interesting  NonZealot | 11/07/06
Sorry  jragosta | 11/07/06
Now I really do feel bad for you  NonZealot | 11/07/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    Click Here