
Here we have another unpatch bug in Internet Explorer as reported by security researchers and those at US-CERT on Thursday. Symantec says this flaw is in an ActiveX control included with Windows 2000, Windows XP, and Windows Server.
informationweek says :
This ActiveX control - WebViewFolderIcon can be used to overflow Internet Explorer's buffer, and inject malicious code to the compromised PCs. It was first first reported in July by HD Moore of Metasploit. "Now that a functional exploit is available, an official patch from Microsoft will likely appear at some point in the future," Symantec said in an alert to customers.






Comment Preview