|
Did the BugBlog help you? Donate via PayPal to say thanks. Even better, subscribe to the BugBlog Plus for even more coverage of bugs and their fixes. Jump to the BugBlog archives
Dec 06
|
BugBlog Bug of the MonthEvery month the BugBlog picks its Bug of the Month, representing the most significant bug found in the past month. Sometimes, the bug will be the one which could potentially cause the most damage; sometimes it will be the bug which affects the most users. And sometimes, it will be the bug that is just the most interesting bug. This bug will be selected either from the free Bug of the Day, or from the subscription-only BugBlog Plus. This month the Bug of the Month goes to Microsoft, for thisActiveX bug that appeared in the BugBlog on October 10. Another bug in an ActiveX control puts users of Windows 2000, Windows XP, and Windows Server 2003 in jeopardy. The bug is in the WebViewFolderIcon ActiveX control, and if you visit a malicious website (using Microsoft Internet Explorer) that tries to exploit this bug, the bad guys may take complete control of your system. This is rated a Critical bug for Windows 2000 and Windows XP by Microsoft, and a moderate bug for Windows Server 2003. Get your patch at http://www.microsoft.com/technet/security/bulletin/ms06-057.mspx, (although there may be some problems with patch availability on 10/10). Why this bug? Actually, it serves as a representative for two different events at Microsoft. The first is the deluge of security bulletins issued by Microsoft in October. There were ten bulletins, that together fixed twenty-five different bugs. A Patch Tuesday this big deserves recognition. The second thing it represents is ActiveX itself. Microsoft chose to emphasize ActiveX, instead of Java, in the 90's, and it wasn't a good decision. Over the years, there have been many security problems with ActiveX controls, and they are still occuring. An ActiveX control from AOL was the Bug of the Day on October 12, and the BugBlog Plus of November 1 reports on an exploit in the Microsoft WMI Object Broker ActiveX control. So for these reasons, Microsoft wins another Bug of the Month.
Previous Bugs of the MonthOctober 2006: Microsoft VML Bug September 2006: Sony Batteries August 2006: Microsoft Windows Genuine Advantage July 2006: Yahoo! Mail June 2006: Symantec Enterprise AV May 2006: Microsoft Wins Special Lifetime Achievement Bug Award April 2006: Adobe Macromedia Flash Player March 2006: Microsoft Windows Media Player Feb 2006: Apple QuickTime Jan 2006: Microsoft WMF Bug Dec 2005: Sony's Secret DRM Scheme Leaves Users Exposed November 2005: Four Separate Bugs Leave Windows Open to Takeover October 2005: Acrobat Screws Up MS Word September 2005: Apple Security Update Breaks 64-bit Apps August 2005: Cisco IOS Vulnerable to IPv6 bug July 2005: RealNetworks Fixes Four Bugs in Their Media Player June 2005: Flawed Rollout for Netscape 8 May 2005: TCP/IP Fix for Windows April 2005: Denial of Service against Symantec Norton AntiVirus March 2005: IDN Spoofing Bug February 2005: Windows Animated Cursor Bug January 2005: Windows Firewall Problems with Dial-up connections The Bug of the Month is also posted at Blogcritics.org
|
||||||||||||||||||||||||