Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2026 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

Yet another IE only problem…

July 7, 2009 By Michael Kavka Leave a Comment

Well, it seems that another problem with Active X Video has gone Zero Day. Drive by (click by?) attacks are now exploiting the hole in the MS972890 advisory. This only affects IE, and only XP and 2003, so yes it is rather limited, but XP and 2003 are still very prevalent in the world.

The advisory does have a link on how to work around the vulnerability with a kill switch setting on the DLL file. Just shows another reason why I would not use IE if the web site does not require it.

Filed Under: General Tagged With: Active X Video, IE, MS97280, Server 2003, Windows XP

RSS Taggart Institute Intel Feed

  • Exposed MongoDB instances still targeted in data extortion attacks February 1, 2026 Bill Toulas
  • New Apple privacy feature limits location tracking on iPhones, iPads February 1, 2026 Sergiu Gatlan
  • AI security startup CEO posts a job. Deepfake candidate applies, inner turmoil ensues. February 1, 2026 Jessica Lyons
  • OpenAI says you can trust ChatGPT answers, as it kicks off ads rollout preparation February 1, 2026 Mayank Parmar
  • OpenAI is retiring famous GPT-4o model, says GPT 5.2 is good enough February 1, 2026 Mayank Parmar
  • Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site February 1, 2026 Matthew Gault
  • America’s Best Chance to Transform Iran January 31, 2026 Ilan Goldenberg
  • Minnesota's effort to end the surge is rejected as journalists are arrested, but pushback continues January 31, 2026 Chris Geidner
  • RINA Accountants & Advisors is creating $400K settlement fund to settle lawsuit over 2022 data breach January 31, 2026 Dissent
  • Comcast agrees to $117.5 million settlement to resolve lawsuits over 2023 Citrix Bleed data breach January 31, 2026 Dissent

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP