[LINK] yet another firefox vulnerability

Malcolm Miles mgm-ns at tardis.net
Mon Sep 12 22:10:43 EST 2005


On Mon, 12 Sep 2005 12:28:04 +1000, you wrote:


>By comparson, the latest Secunia report for MS Internet Explorer
>allows the attacker to gain access to the complete Windows Operating
>Environment IFF. that user visits an untrusted site that executes
>Active-X controls.

The Active-X object in question is shipped or installed with Windows
oe Internet Explorer. It is installed as part of the original releases
of Visual Studio 2002, and Access 2002. The issue was fixed in
subsequent service packs for these products quite some time ago.

>By default, most MS IE installations allow
>execution of Active-X.

Active-X controls can only be installed on a PC by an administrator.
Users cannot install Active-X controls.

-- 
Best wishes,
Malcolm




More information about the Link mailing list