Posted by Luciano Lima | Comments: (0)
Microsoft yesterday released Security Advisory 972890 warning of a vulnerability in an ActiveX control Microsoft Video (msvidctl.dll). It is a fault in the object MPEG2TuneRequest and that can be exploited by a Web page or in rarer cases by a malicious e-mail, which allows the attacker to remotely execute code with the privileges of the user.
The most common scenario exploration of malicious pages are placed on sites specially made for this or inserted by attackers on legitimate sites. The flaw is already being used for attacks on the Internet and affect systems Windows XP and Windows Server 2003. systems Windows Vista, Windows Server 2008 and Windows 2000 Service Pack 4 are not affected.
Microsoft is investigating the problem and will release a fix as soon as possible. While this does not happen you can and should protect your system already disabling this ActiveX control (ie activating the so-called "kill bit" for this control in the registry of your PC). This prevents the vulnerability from being exploited and should not cause any side effects.
To protect your PC automatically, click the button below:
After doing the procedure you must restart Internet Explorer for it to pass to take effect.
In Active Directory environments you can make changes to a building. Reg file and distributed via Group Policy, following the instructions provided in the Security Advisory .
Source: