Vulnerability in Microsoft Video ActiveX Control Could Allow Remote Code Execution
Description
Microsoft has released a patch to fix a vulnerability in Microsoft Video ActiveX Control. An attacker who successfully exploited this vulnerability could execute code with the same user rights as the local user. When using Internet Explorer, code execution is remote and may not require any user intervention.
This vulnerability is being actively exploited.
Versions Affected
- Windows Server 2003;
- Windows XP;
Vendor Response
Microsoft has released security bulletin MS09-032 and a patch for this problem. The patch is available via Windows Updates.
Customers may prevent the Microsoft Video ActiveX Control from running in Internet Explorer, either manually using the instructions in the Workaround section of the security bulletin or automatically by applying the patch. There is no known impact to application compatibility from implementing this workaround.
More Information
