Author Topic: Malicious ActiveX controls in documents  (Read 5102 times)

0 Members and 1 Guest are viewing this topic.

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Malicious ActiveX controls in documents
« on: December 20, 2008, 09:56:41 AM »
"Attackers are exploiting the just-patched vulnerability in Internet Explorer (IE) by hiding malicious ActiveX controls in Microsoft Word documents, according to security researchers.

The rogue documents can be delivered as attachments to spam or offered up by hacked sites. Attackers have been exploiting the IE bug since at least 9 December, when reports first surfaced about malicious code found in the wild and on several Chinese hacker servers.

Since then, Microsoft acknowledged the bug, then offered up a series of advisories urging users to take protective steps until a fix was available, and on Wednesday, Microsoft released the patch.

Users must be cautious about opening Word documents, keep their security software up-to-date, and apply the IE patch as soon as possible."

http://virusbuster.hu/en/viruslab/security_news/081220_ie7flaw4


If you haven't already patched, Now would be a good time.

Be careful out there
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

samuelvirucide

  • Guest
Re: Malicious ActiveX controls in documents
« Reply #1 on: December 20, 2008, 12:05:22 PM »
 :)Hi Marc57,

   Thanks for the infowarning!!!!! ;D By the way I ve read that Kiss will record a new album, excited huh ;D
    http://www.livedaily.com/blog/3041.html

CharleyO

  • Guest
Re: Malicious ActiveX controls in documents
« Reply #2 on: December 20, 2008, 12:31:26 PM »
***

Thanks for posting that info, Marc.


***

spg SCOTT

  • Guest
Re: Malicious ActiveX controls in documents
« Reply #3 on: December 20, 2008, 12:39:08 PM »
If you haven't already patched, Now would be a good time.

would you know how to get the patch for ie because microsoft update doesn't work for me, whenever i choose the option (express or custom) it gives me an error, and when i look up that error i get the page not not fund error. Also I haven't had automatic updates in quite a while could be related...

thanks
« Last Edit: December 20, 2008, 01:03:17 PM by spg SCOTT »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Malicious ActiveX controls in documents
« Reply #4 on: December 20, 2008, 02:54:17 PM »
What's the error message ???
What's your OS ???
The more info you supply, the easier it is for us to help.  :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

spg SCOTT

  • Guest
Re: Malicious ActiveX controls in documents
« Reply #5 on: December 20, 2008, 03:10:07 PM »
I started a new thread for this problem

http://forum.avast.com/index.php?topic=41152.0

there is more info there

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Malicious ActiveX controls in documents
« Reply #6 on: December 20, 2008, 03:17:52 PM »
Why 2 threads on the same subject ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

spg SCOTT

  • Guest
Re: Malicious ActiveX controls in documents
« Reply #7 on: December 20, 2008, 03:18:49 PM »
my impatience and i'm slightly distracted, sorry

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: Malicious ActiveX controls in documents
« Reply #8 on: December 20, 2008, 10:50:38 PM »
If you haven't already patched, Now would be a good time.

would you know how to get the patch for ie because microsoft update doesn't work for me, whenever i choose the option (express or custom) it gives me an error, and when i look up that error i get the page not not fund error. Also I haven't had automatic updates in quite a while could be related...

thanks

Go here and look for your OS and version of IE.

http://www.microsoft.com/downloads/results.aspx?DisplayLang=en&nr=20&freetext=security+update&sortCriteria=date#
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: Malicious ActiveX controls in documents
« Reply #9 on: December 20, 2008, 10:53:12 PM »
:)Hi Marc57,

   Thanks for the infowarning!!!!! ;D By the way I ve read that Kiss will record a new album, excited huh ;D
    http://www.livedaily.com/blog/3041.html

I hadn't heard about that, Thanks for the info!!!

***

Thanks for posting that info, Marc.


***

Your Welcome.
« Last Edit: December 20, 2008, 10:56:56 PM by marc57 »
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!