NEWS

Microsoft ActiveX Control Wins the Bug of the Month

Written by Bruce Kratofil
Published November 02, 2006
Part of BugBlog

Every month the BugBlog picks its Bug of the Month, representing the most significant bug found in the past 30 days. Sometimes, the bug will be the one which could potentially cause the most damage; sometimes it will be the bug which affects the most users. And sometimes, it will be the bug that is just the most interesting.

This month the Bug of the Month goes to Microsoft, for this ActiveX bug that appeared in the BugBlog on October 10.

Another bug in an ActiveX control puts users of Windows 2000, Windows XP, and Windows Server 2003 in jeopardy. The bug is in the WebViewFolderIcon ActiveX control, and if you visit a malicious website (using Microsoft Internet Explorer) that tries to exploit this bug, the bad guys may take complete control of your system. This is rated a Critical bug for Windows 2000 and Windows XP by Microsoft, and a moderate bug for Windows Server 2003. Get your patch (although there may be some problems with patch availability on 10/10).

Why this bug? Actually, it serves as a representative for two different events at Microsoft. The first is the deluge of security bulletins issued by Microsoft in October. There were ten bulletins that, together, fixed twenty-five different bugs. A patch Tuesday, this big deserves recognition.

The second thing it represents is ActiveX itself. Microsoft chose to emphasize ActiveX, instead of Java, in the '90s, and it wasn't a good decision. Over the years, there have been many security problems with ActiveX controls, and they are still occurring. An ActiveX control from AOL was the Bug of the Day on October 12, and the BugBlog Plus of November 1 reports on an exploit in the Microsoft WMI Object Broker ActiveX control.

So for these reasons, Microsoft wins another Bug of the Month.

Bruce Kratofil blogs on bugs and other things that can go wrong with your computer at The BugBlog, and writes about computers and economics at BJK Research
Keep reading for information and comments on this article, and add some feedback of your own!
Microsoft ActiveX Control Wins the Bug of the Month
Published: November 02, 2006
Type: News
Section: Sci/Tech
Filed Under: Sci/Tech: Computers, Sci/Tech: Internet, Sci/Tech: Programming, Sci/Tech: Software
Part of a feature: BugBlog
Writer: Bruce Kratofil
Bruce Kratofil's BC Writer page
Bruce Kratofil's personal site
Spread the Word
Like this article?
Email this
Submit to del.icio.us Save to del.icio.us
RSS Feeds
All RSS Feeds (240+)
Comments on this article
Articles in this series
BC articles by Bruce Kratofil
Sci/Tech: Computers
Sci/Tech: Internet
Sci/Tech: Programming
Sci/Tech: Software
All Sci/Tech Articles
Bruce Kratofil's personal weblog
All News articles
All BC articles
All BC Comments

Comments

Want comments emailed to you? No spam, promise! Address:

Add your comment, speak your mind

(Or ping: http://blogcritics.org/mt/tb/55242)

Personal attacks are not allowed. Please read our comment policy.





Remember Name/URL?

Please preview your comment!

Fresh
Articles
Fresh
Comments