The Register®

Original URL: http://www.theregister.co.uk/2006/11/06/0-day_windows_bug/

0-day bug shatters Windows

Mother, it's happening again

By John Leyden

Posted in Anti-Virus, 6th November 2006 14:30 GMT

Security researchers have identified an unpatched vulnerability in Windows. The flaw - which affects all supported versions of Windows bar Windows 2003 - resides in a security bug in Microsoft XML Core Services, specifically an unspecified security bug in the XMLHTTP 4.0 ActiveX Control.

The flaw creates a means for hackers to inject malware onto the PCs of surfers running IE who visit a website hosting malicious code that attempts to harness the security bug. Security notification firm Secunia says (http://secunia.com/advisories/22687/) that the vulnerability is being actively exploited by hackers.

Microsoft has posted an advisory (http://www.microsoft.com/technet/security/advisory/927892.mspx) conceding the problem and suggesting possible workarounds, which basically involve disabling the affected ActiveX control, ahead of the arrival of a patch. ®