<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.thestandard.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The Industry Standard - Microsoft confirms attacks against IE6, IE7 - Comments</title>
 <link>http://www.thestandard.com/news/2009/07/06/microsoft-confirms-attacks-against-ie6-ie7</link>
 <description>Comments for &quot;Microsoft confirms attacks against IE6, IE7&quot;</description>
 <language>en</language>
<item>
 <title>Microsoft confirms attacks against IE6, IE7</title>
 <link>http://www.thestandard.com/news/2009/07/06/microsoft-confirms-attacks-against-ie6-ie7</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;
&lt;p&gt;For the second time in six weeks, Microsoft today confirmed that hackers are exploiting an unpatched bug in DirectX, this time by attacking Internet Explorer (IE).&lt;/p&gt;
&lt;p&gt;The company&#039;s security team issued an &lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/972890.mspx&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot;&gt;advisory&lt;/a&gt; Monday around 1 p.m. ET acknowledging reports of in-the-wild attacks and providing more information about who is vulnerable.&lt;/p&gt;
&lt;p&gt;Earlier today, security researchers at a pair of Danish firms had announced that thousands of legitimate Web sites hacked over the weekend were conducting &lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9135210&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot;&gt;drive-by attacks&lt;/a&gt; on IE users with an exploit of a critical unpatched vulnerability in Windows&#039; DirectShow, part of DirectX.&lt;/p&gt;
&lt;p&gt;&quot;A browse-and-get-owned attack vector exists,&quot; Chengyun Chu, of the Microsoft Security Response Center&#039;s engineering team, said in a &lt;a href=&quot;http://blogs.technet.com/srd/archive/2009/07/06/new-vulnerability-in-mpeg2tunerequest-activex-control-object-in-msvidctl-dll.aspx&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot;&gt;blog post&lt;/a&gt; this afternoon. &quot;A user needs to be lured to navigate to a malicious Web site or a compromised legitimate Web site to be affected ... [but] no further user interaction is needed.&quot;&lt;/p&gt;
&lt;p&gt;Users running IE6 or IE7 on Windows XP and Windows Server 2003 are vulnerable to the drive-bys attacks, Microsoft said. Vista and Server 2008 are not at risk, however, nor are people running IE8, Microsoft&#039;s newest browser.&lt;/p&gt;
&lt;p&gt;Although Microsoft promised it would patch the bug, a company spokesman declined to say whether that patch would be ready by July 14, the next regularly-scheduled security update release day.&lt;/p&gt;
&lt;p&gt;To protect at-risk PCs in the meantime, the company urged users to set 45 &quot;kill bits&quot; in the flawed ActiveX control that contains the vulnerability. That ActiveX control, Microsoft admitted, wasn&#039;t intended to be used by IE. &quot;We identified that none of the ActiveX Control Objects hosted by msvidctl.dll are meant to be used in IE,&quot; said Chu. &quot;Therefore, we recommend to kill-bit all of these controls as a defense-in-depth practice. The side effect is minimal.&quot;&lt;/p&gt;
&lt;p&gt;Setting ActiveX kill bits can be dangerous, as it involves editing the Windows registry. &quot;If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system,&quot; Microsoft warned in its advisory. &quot;Use Registry Editor at your own risk.&quot;&lt;/p&gt;
&lt;p&gt;An easier way to set the kill bits is to run a custom downloadable automated tool that Microsoft&#039;s crafted. The company offered a similar tool as a workaround for the &lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9133648&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot;&gt;other DirectShow bug&lt;/a&gt; it acknowledged in late May.&lt;/p&gt;
&lt;p&gt;The new tool can be downloaded from &lt;a href=&quot;http://support.microsoft.com/kb/972890&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot;&gt;Microsoft&#039;s support site&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9135210&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot;&gt;An earlier report&lt;/a&gt; in Computerworld credited the Danish company CSIS Security Group with first publicizing the DirectShow vulnerability. Actually, Chinese security forums and antivirus firms, including Kingsoft ( &lt;a href=&quot;http://translate.google.com/translate?js=n&amp;amp;prev=_t&amp;amp;hl=en&amp;amp;ie=UTF-8&amp;amp;u=http%3A%2F%2Fblog.duba.net%2Fread.php%2F225.htm&amp;amp;sl=zh-CN&amp;amp;tl=en&amp;amp;history_state0=&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot;&gt;Google Translate translation&lt;/a&gt;), were the first to document the bug.&lt;/p&gt;
&lt;p&gt;Users running a non-Microsoft browser, such as Mozilla&#039;s Firefox or Google&#039;s Chrome, are safe from attack.&lt;/p&gt;
</description>
 <comments>http://www.thestandard.com/news/2009/07/06/microsoft-confirms-attacks-against-ie6-ie7#comments</comments>
 <category domain="http://www.thestandard.com/taxonomy/term/1573">Antispam</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1402">IDGNS</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1556">Operating systems</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1428">Security</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1520">Software</category>
 <category domain="http://www.thestandard.com/taxonomy/term/5667">Software &amp;amp; Web</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1431">Windows</category>
 <category domain="http://www.thestandard.com/taxonomy/term/98">Breaking News</category>
 <pubDate>Mon, 06 Jul 2009 21:23:49 -0400</pubDate>
 <dc:creator>IDG News Service</dc:creator>
 <guid isPermaLink="false">136892 at http://www.thestandard.com</guid>
</item>
</channel>
</rss>
