Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

ActiveX bugs pose threat to Vista, Microsoft reports

Company's security work pays off, but third-party browser add-ons still a problem

November 3, 2008 12:00 PM ET

Active Comments
CodeDog says: They are trying to help ActiveX developers write more secure controls when the real problem is that the really bad...
Anonymous says: Instead of Active X, users should use OS X. Problem solved. With each new service pack and Windows release we...


Computerworld - Although computers running Windows Vista are significantly less likely to be infected with attack code than machines running Windows XP, the newer operating system continues to be threatened by Microsoft Corp.'s own ActiveX browser plug-in technology, according to a report issued Monday by the company.

In the most recent installment of its twice-yearly security intelligence report, Microsoft said that PCs running Windows XP Service Pack 2 (SP2) were more than three times as likely to be infected with malware as computers running Windows Vista SP1. Machines powered by the newest XP security update, SP3, meanwhile, were more than twice as likely to be infected.

According to Microsoft, in the six months from January to June, its Malicious Software Removal Tool (MSRT) cleaned malware from just three Vista SP1 machines per thousand times the tool was run. Meanwhile, during the same period, MSRT found and wiped malicious code from 10 Windows XP SP2 systems and eight XP SP3 PCs per thousand executions. Microsoft updates and automatically redistributes the software tool to Windows users each month on Patch Tuesday.

"Our security development processes do pay off," said George Stathakopoulos, the general manager of Microsoft's product security and security engineering group, referring to work the company has put into writing more secure code for its newer software, including Vista. "We're fairly happy where Microsoft is," Stathakopoulos continued, "but ecosystemwide, we still have a problem."

That's evident from Microsoft's data for the past six months. During that time, while half of the top 10 browser-based attacks against Windows XP machines relied on vulnerabilities in Microsoft's own software, none of the top 10 attacks against Vista systems did. Instead, the overwhelming majority of the browser attacks targeting Vista leveraged bugs in third-party companies' ActiveX controls.

Vulnerabilities in ActiveX, the Microsoft technology used to create add-ins for Internet Explorer (IE), accounted for eight of the top 10 browser-based attacks against Vista in the first half of 2008. A ninth vulnerability could be exploited via ActiveX, among other means.

Two of the eight vulnerability ActiveX controls were part of RealNetworks Inc.'s RealPlayer media player plug-in; another was part of Apple Inc.'s QuickTime player. Both vendors have had to repeatedly patch their programs this year. Apple alone has patched a total of 30 QuickTime vulnerabilities in five updates in 2008.

Microsoft's numbers echo data collected by Symantec Corp. for the latter half of 2007, when ActiveX bugs accounted for 79% of all those discovered in browser plug-ins during that period.

Stathakopoulos defended ActiveX but acknowledged that it was impossible for Microsoft to police its technology. "You have to enable [add-on] development for the browser," he said. "The question is, how do you extend the browser and at the same time provide guidance to developers on how to write secure [ActiveX controls]?" he said.



Jump to comments

Microsoft

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs