Microsoft confirms attacks against IE6, IE7

'Browse-and-own' bug lets hackers hijack Windows XP; temp fix available

For the second time in six weeks, Microsoft today confirmed that hackers are exploiting an unpatched bug in DirectX, this time by attacking Internet Explorer (IE).

The company's security team issued an advisory Monday around 1 p.m. ET acknowledging reports of in-the-wild attacks and providing more information about who is vulnerable.

Earlier today, security researchers at a pair of Danish firms had announced that thousands of legitimate Web sites hacked over the weekend were conducting drive-by attacks on IE users with an exploit of a critical unpatched vulnerability in Windows' DirectShow, part of DirectX.

"A browse-and-get-owned attack vector exists," Chengyun Chu, of the Microsoft Security Response Center's engineering team, said in a blog post this afternoon. "A user needs to be lured to navigate to a malicious Web site or a compromised legitimate Web site to be affected ... [but] no further user interaction is needed."

Users running IE6 or IE7 on Windows XP and Windows Server 2003 are vulnerable to the drive-bys attacks, Microsoft said. Vista and Server 2008 are not at risk, however, nor are people running IE8, Microsoft's newest browser.

Although Microsoft promised it would patch the bug, a company spokesman declined to say whether that patch would be ready by July 14, the next regularly-scheduled security update release day.

To protect at-risk PCs in the meantime, the company urged users to set 45 "kill bits" in the flawed ActiveX control that contains the vulnerability. That ActiveX control, Microsoft admitted, wasn't intended to be used by IE. "We identified that none of the ActiveX Control Objects hosted by msvidctl.dll are meant to be used in IE," said Chu. "Therefore, we recommend to kill-bit all of these controls as a defense-in-depth practice. The side effect is minimal."

Setting ActiveX kill bits can be dangerous, as it involves editing the Windows registry. "If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system," Microsoft warned in its advisory. "Use Registry Editor at your own risk."

An easier way to set the kill bits is to run a custom downloadable automated tool that Microsoft's crafted. The company offered a similar tool as a workaround for the other DirectShow bug it acknowledged in late May.

The new tool can be downloaded from Microsoft's support site.

An earlier report in Computerworld credited the Danish company CSIS Security Group with first publicizing the DirectShow vulnerability. Actually, Chinese security forums and antivirus firms, including Kingsoft ( Google Translate translation), were the first to document the bug.

Users running a non-Microsoft browser, such as Mozilla's Firefox or Google's Chrome, are safe from attack.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags MicrosoftInternet Explorerie8ie7

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Gregg Keizer

Gregg Keizer

Computerworld
Show Comments

Brand Post

Shining a light on creativity

MSI has long pushed the boundaries of invention with its ever-evolving range of laptops but it has now pulled off a world first with the new MSI Creative 17.

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?