|
![]() |
|
|
|
Vulnerability Note VU#545228Microsoft Office Web Components Spreadsheet ActiveX control vulnerabilityOverviewThe Microsoft Office Web Components Spreadsheet ActiveX controls (OWC10 and OWC11) contain a vulnerability that may allow an attacker to take control of a vulnerable system.I. DescriptionThe Office Web Components Spreadsheet ActiveX control contains a code execution vulnerability. Public reports indicate that this vulnerability is being actively exploited.Per the MSRC blog, the following products may install the affected control on a system:
II. ImpactA remote attacker may be able to take control of a vulnerable system.III. SolutionInstall the updates described in Microsoft Security Bulletin MS09-043.Disable the Office Web Components Spreadsheet ActiveX controls in Internet Explorer
{0002E559-0000-0000-C000-000000000046} (OWC11)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E541-0000-0000-C000-000000000046}] "Compatibility Flags"=dword:00000400 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E541-0000-0000-C000-000000000046}] "Compatibility Flags"=dword:00000400 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E559-0000-0000-C000-000000000046}] "Compatibility Flags"=dword:00000400 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{0002E559-0000-0000-C000-000000000046}] "Compatibility Flags"=dword:00000400 Disabling ActiveX controls in the Internet Zone (or any zone used by an attacker) appears to prevent exploitation of this and other ActiveX vulnerabilities. Instructions for disabling ActiveX in the Internet Zone can be found in the Securing Your Web Browser document. Systems Affected
Referenceshttp://www.cert.org/tech_tips/securing_browser/ Thanks to Microsoft for information that was used in this report. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||
![]() |
|||||||||||||||||||||||||||||||