Posted on 07/13/2009 3:24:20 AM PDT by Gomez
A critical ActiveX vulnerability used by hackers to exploit Microsoft Corp.'s Internet Explorer browser is a prime candidate for another Conficker-scale attack, security experts said.
On July 6, just hours after security companies reported that thousands of compromised sites were serving up exploits, Microsoft acknowledged the flaw in the ActiveX control that can be accessed using IE. The bug has been used by hackers since at least June 9.
Microsoft said it will issue a patch for the flaw on July 14.
The vulnerability "exposes the whole world and can be exploited through the firewall," said Roger Thompson, chief research officer at security software vendor AVG Technologies USA Inc. "That's better than Conficker, which mostly did its damage once it got inside a network."
I am assuming this has to do with only XP and server 2003, right?
Never assume with MS.

I already downloaded my "patch".
Firefox on Ubuntu too. Of course it also helps that I don’t download videos (or anything else) from random websites.
When will people learn to stop using a security hole to access the internet?
I fix people’s malware’d machines fairly regularly. The question I always get “What anti-virus should I get, this was a real pai”? I always answer “Get firefox”. Those that listen don’t bring their machines back to me.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.