July 07, 2008

Update: Microsoft warns of new Access attack

The attack, which uses a flaw in the Snapshot Viewer ActiveX control, appears to be targeted rather than widespread

Cybercriminals are exploiting a bug in software used by Microsoft's Access database program in a new online attack, Microsoft warned Monday.

The flaw lies in the Snapshot Viewer ActiveX control, which ships with "all supported versions of Microsoft Office Access except Microsoft Access 2007," Microsoft said in a security advisory, published Monday.

Microsoft released few details of how the bug is actually being exploited, but said that it is investigating an ongoing computer attack that takes advantage of the problem. "The attack appears to be targeted, and not widespread," wrote Bill Sisk, a Microsoft spokesman, in a blog posting.

Attackers are trying to lure victims to a specially crafted Web page that tries to run the attack code within Internet Explorer. The bug gives attackers a way to run their malicious software on the victim's machine.

Microsoft's Security Advisory offers a number of possible work-arounds for the problem, but the company has not said when it plans to fix the underlying bug.

"We encourage affected customers to implement the manual work-arounds included in the Advisory, which Microsoft has tested," Sisk said. "Although these work-arounds will not correct the underlying vulnerability, they help block known attack vectors."

Snapshot Viewer lets PC users view a Microsoft Access report without having to run the Access software itself. It can be downloaded as stand-alone software.

Because the vulnerable ActiveX control is digitally signed by Microsoft, some users could be attacked even if they haven't installed the Snapshot Viewer control. Victims who have configured Internet Explorer to trust Microsoft software could be forced to silently download the buggy viewer and then be attacked via the Web, said Matthew Richard, director of VeriSign's iDefense Rapid Response Team.

Microsoft has made a concerted effort to lock down its core Windows operating system over the past five years and, as a result, hackers have increasingly turned to third-party software and ActiveX components like Snapshot Viewer when looking for bugs.

In April, criminals began using software that included attack code for seven ActiveX bugs, including flaws in controls made by Microsoft, Citrix Systems, Hewlett-Packard, Sony, and D-Link.

This latest issue is "another in the long line of ActiveX bugs," said Andrew Storms, director of security operations with nCircle, via instant message. "It's disheartening to see yet another ActiveX problem."

Close

On Twitter now

Application development

Powered by Twitter

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Subscribe to the Developer World Newsletter

Receive a weekly roundup about the art and science of software development.

©1994-2009 Infoworld, Inc.