Microsoft is throttling a potentially evil paperclip this Patch Tuesday: Namely, a critical vulnerability in its Microsoft Agent—aka "Clippy"—that can open a system up to hijacking.

The security advisory for Microsoft Agent, MS07-051, is the only critical release out of four security advisories the company put out on Sept. 11. It addresses a vulnerability whereby Clippy can get hoodwinked by a malicious URL and can then be used to take over a targeted system without ever appearing to the user.

Clippy—officially known as Clippit—met its demise in Office 2007, but this vulnerability still affects the agent as it exists in Microsoft Windows 2000 SP4.

Given that this vulnerability is rated critical and can lead to system takeover, some rank it at the top of the priority list for patching if users are running Windows 2000. "This one is critical, and it's like a browser fix: You surf to an evil Web site and you'll get hacked," said Eric Schultze, chief security architect at Shavlik Technologies.

Symantec's Security Response is considering the Agent flaw to be a high-priority fix given that it's in Microsoft Agent's ActiveX, which runs on a "significant number of systems," the company said in a release. Beyond its ubiquity, the vulnerability is yet another hallmark of a big bump in the number of ActiveX vulnerabilities



Copyright (c) 2007 Ziff Davis Media Inc. All Rights Reserved.
http://www.pcmag.com/print_article2/0,1217,a=215006,00.asp
arrow
arrow
    全站熱搜
    創作者介紹
    創作者 ivan0914 的頭像
    ivan0914

    I'n Blog 之萬象真藏

    ivan0914 發表在 痞客邦 留言(0) 人氣()