Joshua, I get a security warning that the ActiveX control cannot be launched. I've customized my IE settings somewhat though. I don't like surprises. :-)
kabuki, yeah, that's my piont. The seems to be on this folder issue. If, however, an attacker can remotely write to my filesystem, I'd say that's a far worse issue. From the sound of the exploit, it seems that this remote write is possible. Otherwise, this is about as exciting as sending an HTML doc with some VBScript that does bad stuff using FileSystemObject. IOW, I don't see this as anything new.
|