<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Real-time AntiSpam protection, automated and self-managed content filtering &#187; ActiveX Exploit</title>
	<atom:link href="http://veriat.com/tag/activex-exploit/feed" rel="self" type="application/rss+xml" />
	<link>http://veriat.com</link>
	<description></description>
	<lastBuildDate>Thu, 27 May 2010 23:10:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New Features Expose Windows Systems to Malicious Attacks</title>
		<link>http://veriat.com/new-features-expose-windows-systems-to-malicious-attacks.html</link>
		<comments>http://veriat.com/new-features-expose-windows-systems-to-malicious-attacks.html#comments</comments>
		<pubDate>Sun, 02 Aug 2009 12:55:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Anti-spam techniques]]></category>
		<category><![CDATA[ActiveX Exploit]]></category>
		<category><![CDATA[Malicious Attacks]]></category>
		<category><![CDATA[Microsoft's Office Suite]]></category>
		<category><![CDATA[Outlook View]]></category>

		<guid isPermaLink="false">http://veriat.com/?p=273</guid>
		<description><![CDATA[Outlook View ActiveX Vulnerability
We&#8217;ve all heard the saying, &#8220;The only things guaranteed in life are death and taxes!&#8221; Well, some people are beginning to think that we need to add a third item to that list of sure things. &#8220;The only things guaranteed in life are death, taxes and new security vulnerabilities with each incarnation [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Outlook View ActiveX Vulnerability</strong></p>
<p>We&#8217;ve all heard the saying, &#8220;The only things guaranteed in life are death and taxes!&#8221; Well, some people are beginning to think that we need to add a third item to that list of sure things. &#8220;The only things guaranteed in life are death, taxes and new security vulnerabilities with each incarnation of Microsoft&#8217;s Office Suite.&#8221; Yesterday, noted Bulgarian security consultant, Georgi Guninski, went public with a security advisory for Office XP users that would allow a malicious web developer unencumbered access to a victim&#8217;s e-mails. Simply by visiting a web page or opening a web enabled e-mail message, an Outlook user would unwittingly expose not only Outlook, but also the entire Windows system to the attacker. Further testing by KeyLabs, and after a subsequent security bulletin issued by Microsoft, we now know that this vulnerability affects Outlook 98 and Outlook 2000 as well as Outlook 2002 (part of the Office XP suite).<span id="more-273"></span></p>
<p>At the heart of the problem is the new &#8220;Microsoft Outlook View Control.&#8221; This ActiveX control allows Outlook features (i.e. e-mails, folders, calendar events, or contacts) to be displayed in web pages. Originally intended to only allow passive operations such as viewing data, this control unintentionally grants privileged access, which would allow the hacker to manipulate data. This bug goes far beyond simply manipulating e-mail messages. In our testing with KeyLabs, BugNet was able to go so far as to delete files from the victim&#8217;s computer as well as run executables &#8211; all without user intervention.</p>
<p><strong> ActiveX Exploit </strong></p>
<p>Exploiting this vulnerability involves creating a web page or HTML-enabled e-mail message with the embedded Outlook View ActiveX control. Once invoked, the control allows the HTML code (and any subsequent scripts) to run with elevated privileges on the victim&#8217;s system.</p>
<p>The Outlook View ActiveX control installs by default with Office XP, but also affects Outlook 98 and Outlook 2000. In our tests we found that the ActiveX control will download and install automatically (after the users verifies the Microsoft certificate) when IE encounters the object in a web page.</p>
<p>Make no mistake; this is a serious security breach. So much so that Microsoft issued a security bulletin without having a patch available. At the time of this writing, Microsoft is preparing a patch that will eliminate this bug, but also warns users that in the meantime, they should disable ActiveX controls in the Internet Zone.</p>
<p>Installing the previously released Outlook E-mail Security Update would eliminate half of this vulnerability. This security update was created over a year ago in answer to the e-mail borne worms and viruses like ILY. Installing this patch would eliminate e-mail as a vehicle of attack, but wouldn&#8217;t prevent a web page from infiltrating the system. For that, you will need to adjust IE&#8217;s security settings.</p>
<p><strong>Workaround is the Only Option</strong></p>
<p>We strongly recommend that users adjust their security settings appropriately. One simple way to do this is to adjust the security setting for the Internet Zone to High. Do this by starting Internet Explorer and clicking on Tools &gt; Internet Options &gt; Security. Select the Internet Zone and move the Security Level slider bar all the way to the top. This will lock down IE and prevent ActiveX and other scripting from running in the browser.</p>
<p>Be aware that by selecting IE&#8217;s highest security setting, many legitimate web sites will not function properly in the browser. Adding these web sites to the trusted sites zone will let them function as designed, yet still protect your system from rogue web sites.</p>
]]></content:encoded>
			<wfw:commentRss>http://veriat.com/new-features-expose-windows-systems-to-malicious-attacks.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
