myITforum.com

Welcome to myITforum.com Sign in | Join | Help
in Search

Harry Waldron - My IT Forums Blog

Sharing Security Developments, and Best Practices for corporate and home users

MS07-009: ADODB ActiveX based Exploit Code

The MS07-009 patch should be applied by most companies and home users.  However, if someone isn't patched, they should do so quickly in light of this recent development.

http://www.us-cert.gov/current/current_activity.html#ADODBActiveX

quote:

US-CERT is aware of publicly available exploit code for a vulnerability in the Microsoft ADODB.Connection ActiveX Control. The vulnerability in the ADODB.Connection ActiveX object causes memory corruption, and may allow a remote, unauthenticated attacker to cause Internet Explorer to crash or potentially execute arbitrary code.

More information about this vulnerability can be found in the following:

  • Vulnerability Note VU#589272- ADODB.Connection ActiveX control memory corruption vulnerability
  • Microsoft Security Bulletin MS07-009

US-CERT recommends the following actions to help mitigate the security risks:

Comments

No Comments
Powered by Community Server (Commercial Edition), by Telligent Systems