Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.
Unfortunately, one of the three ATL vulnerabilities makes it possible to bypass the kill bit mechanism that is supposed to prevent the use of vulnerable ActiveX controls in Internet Explorer. A recent example is the kill bit for the Microsoft Video ActiveX control that was set in this month's Patch Tuesday updates.
An ActiveX control containing an ATL vulnerability could thus be used to activate another control which can be exploited to take over the system.
And that's where the second out of cycle update comes in. An update for Internet Explorer blocks all known ATL vulnerabilities in controls loaded by the browser.
The IE update also introduces - but does not enable - a mechanism that blocks the use of the two interfaces involved in the ATL vulnerabilities. Users or administrators who choose to enable this feature may whitelist particular controls that are known to be safe.
In addition, the update addresses three vulnerabilities that can be exploited by maliciously crafted web pages to execute code with the same rights as the current user.
Available for IE 5, 6, 7 and 8, the update is regarded as critical on Windows 2000, XP and Vista, and moderate on Server 2003 and 2008.
So why did Microsoft rush out updates for vulnerabilities that are apparently not being actively exploited? After all, the active attack on the Microsoft Video ActiveX control had already been blocked by the July Patch Tuesday updates.
According to Jonathan Ness of the Microsoft Security Response Center, "with the Black Hat and Def Con security conference getting people together around the same watering hole, natural curiosity means that risk to customers could increase as more information is disclosed."
David Bass
| ComOps, a leading Australian provider of business software products and services, has won a competitive tender to deploy its Salvus safety, r…
How to Make Business Discovery Work for Your Business
Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more
Try an easy-to-use set of web-enabled
tools for business-class productivity services. Office 365 provides
anywhere-access to email, important documents, contacts, and calendars
on almost any device.