Since its introduction, Microsoft's ActiveX technology has been plagued by a seemingly endless flow of security vulnerabilities. The latest flaw discovered by famed bug-hunter Georgi Guninski does nothing to soften the technology's bug laden image. This time, Microsoft Outlook View Control, an ActiveX control that ships with Office XP, grants malicious users unprecedented access to a target system. According to Guninski's findings, "If a user visits a specially designed HTML page with IE or opens or previews a message with Outlook XP arbitrary commands may be executed on his computer." This exploit is accomplished by accessing the Outlook executable, allowing an intruder to read, modify, or delete messages contained in Outlook XP's folders using a property called "selection."
|