Network and Computer Security

The Network and Computer Security Blog

Bookmark this site!

November 6, 2006

Microsoft XMLHTTP ActiveX Control Code Execution Vulnerability

Filed under: News, Vulnerabilities, Windows, Articles — SecuNews @ 2:58 pm

A vulnerability has been reported in Microsoft XML Core Services, which can be exploited by malicious people to compromise a users system.

The vulnerability is caused due to an unspecified error in the XMLHTTP 4.0 ActiveX Control.

Successful exploitation allows execution of arbitrary code when a user e.g. visits a malicious website using Internet Explorer.

Microsoft Advisory & Suggested Workarounds: http://www.microsoft.com/technet/security/advisory/927892.mspx

Leave a Reply

You must be logged in to post a comment.