Another IE zero day exploited

Second DirectShow vulnerability in six weeks labelled 'extremely critical'.

Microsoft has issued an advisory on a serious vulnerability in an ActiveX control in its Internet Explorer browser, the second zero-day alert in the same area of the product in recent months. The issue has been flagged as 'extremely critical' by vulnerability watchers at Secunia, and several reports of active exploitation in the wild have been seen, including some high-profile sites in China.

Advertise on www.virusbtn.com

The flaw affects the DirectShow video streaming subsystem, hit by a similarly high-profile zero-day flaw in late May. This time the MSVidCtl.dll library is affected, and maliciously crafted files passed into affected systems can be used to remotely hijack vulnerable machines via silent drive-by download infections. The flaw is believed not to affect users of Microsoft's latest operating system versions, Vista and Server 2008.

The official advisory from Microsoft is here, with alerts and workarounds from Secunia here and SANS ISC here. More info is blogged by Trend Micro here and ScanSafe here, with a McAfee blog piece providing details of a range of similar attacks and an attractive diagram of the attack vector, here. A similar diagram can be found in a post from the MMPC on the previous DirectShow issue, here.

07 July 2009

Tags: advisory, exploit, internet explorer, microsoft, vulnerability, workaround, zero day.   

 del.icio.us  digg this! digg this

0 comments

Leave a comment

Quick Links

Poll
The Japanese government is reported to have commissioned a 'defensive virus'. Is 'defensive' malware ever a good idea?
Yes
No
I don't know
Leave a comment
View 11 comments

99 Subscription Promo

VB100 certification
VB100 This month's VB100 test saw some major changes and a radical overhaul of the VB100 test methodology - for the first time allowing products to use their 'cloud' look-up systems. John Hawes has all the details.
See full results.

Virus Bulletin currently has 224,223 registered users.