A vulnerability in Microsoft’s XML HTTP request-handling can be exploited via an ActiveX control through a Web browser — specifically Internet Explorer — according to IBM’s Internet Security Systems, which claims to have originally identified the flaw. The vulnerability, which is currently being leveraged by spyware producers to install malware on exposed computers, is unpatched and active in the wild, said Gunter Ollmann, Director of X-Force for IBM Internet Security Systems.
Report: Microsoft XML Exploit Unpatched and in the Wild
Posted by: Erika Morphy November 8, 2006 07:30 AMA vulnerability in Microsoft’s XML HTTP request-handling can be exploited via an ActiveX control through a Web browser — specifically Internet Explorer — according to IBM’s Internet Security Systems, which claims to have originally identified the flaw. The vulnerability, which is currently being leveraged by spyware producers to install malware on exposed computers, is unpatched and active in the wild, said Gunter Ollmann, Director of X-Force for IBM Internet Security Systems.