Microsoft Warns Users of 'Zero Day' Security Issue

Latest Videos FromTom's Hardware
Jane McEntegart
Contributor

Jane McEntegart is a writer, editor, and marketing communications professional with 17 years of experience in the technology industry. She has written about a wide range of technology topics, including smartphones, tablets, and game consoles. Her articles have been published in Tom's Guide, Tom's Hardware, MobileSyrup, and Edge Up.

  • crom
    Yet another example of the many reasons to never use Internet Explorer.
    Reply
  • Shadow703793
    Ummm... OK. I live off of FireFox lol. Anyways, wish they would get rid of ActiveX permanently. They SHOULD do that in Windows 8, esp. since IE is going downhill and ActiveX is part of that problem.
    Reply
  • offkey_toms
    A popular misconception concerning the firefox add-on (based on NPAPI technology) is that a add-on is somehow inherently safer than an ActiveX control. Both run native machine instructions with the same privileges as the host process. Thus a malicious plugin can do as much damage as a malicious ActiveX control.

    People, wake up...


    Reply
  • Shadow703793
    offkey_tomsA popular misconception concerning the firefox add-on (based on NPAPI technology) is that a add-on is somehow inherently safer than an ActiveX control. Both run native machine instructions with the same privileges as the host process. Thus a malicious plugin can do as much damage as a malicious ActiveX control.People, wake up...True, but the other parts of the IE structure allows for the easier installation of ActiveX plug-ins without the users knowledge. And has a greater ability to do damage to a system.

    Also NPAPI runs just on the browser itself while ActiveX can run as part of other programs, esp. VB, thus making ActiveX a bigger security hole than NPAPI ad-ons which is restricted mainly to the browser.
    Reply
  • tmike
    The small trickle of updates to Windows are far easier to swallow than the daily stream of notices I receive about new defects and vulnerabilities in Debian.
    Reply
  • jhansonxi
    tmikeThe small trickle of updates to Windows are far easier to swallow than the daily stream of notices I receive about new defects and vulnerabilities in Debian.Most Linux distro package managers update every application installed, not just the OS and web browser. The distros are very paranoid and proactive (although probably not as much as OpenBSD).
    Reply
  • SAL-e
    "In the meantime, our investigation has shown that there are no by-design uses for this ActiveX Control within Internet Explorer. ...
    Why the hell if the ActiveX Control has no useful use, can be run remotely and can not be uninstalled?
    Reply
  • SAL-e: It was probably a backdoor in the first place... Or else Microsoft is utterly incompetent, you choose...
    Reply
  • dafin0
    cromYet another example of the many reasons to never use Internet Explorer.
    no yet another reason to update you software,no one should be using IE6/7 anymore so if anything happens to them then its there own fault
    (btw) the article doesn't seam to state this only effects IE6/7
    Reply
  • Core2uu
    More than your punishment for using IE, it's your punishment for continuing to use a decade old OS.

    Cmon people, let's move, the turn of the century was almost 10 years ago.
    Reply