iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > News > Security News > ActiveX Poses New Problem For IE
Search:
[ news_security_news ]

ActiveX Poses New Problem For IE



David Utter
Staff Writer
2006-07-06

SecurityProNews: Insider Reports Insider Reports RSS Feed


A highly critical vulnerability in the Internet Explorer browser's HTML Help could be exploited to gain remote system access on a machine.

An advisory posted by Secunia's tracking service noted the latest problem to bedevil Internet Explorer users.

A memory corruption condition could be a problem for IE users, should it be exploited. The flaw could permit the execution of arbitrary code on a system.

"The vulnerability is caused due to an error in the HTML Help ActiveX control (hhctrl.ocx) when handling the "Image" property," Secunia noted in its advisory.

"This can be exploited to cause a memory corruption by setting an overly long string multiple times for the property."

The problem has been confirmed on a fully patched system with all patches in place for Windows XP SP2, running Internet Explorer 6.0.

An advisory from Microsoft is not currently available. Secunia recommends disabling the "Run ActiveX controls and plug-ins" setting for all but trusted sites until the issue has been corrected.

Issues like these have been a nigh-regular occurrence in IE. And the potential for a crippling wave of Trojan horse attacks on Windows platforms have become so great, one security company recommended that home users should consider a Mac for their computing needs.

For those who want to or need to stay in Windows, freely available browser options from Opera and Firefox are available for consideration.

---
Tags: ,

Add to Del.icio.us | Digg | Yahoo! My Web | Furl

Get all the updates in RSS:





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More news_security_news Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds