Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Over the Horizon>Microsoft skips some critical IE patches

Microsoft skips some critical IE patches

Tweet

Chris mosby By Chris Mosby

The "squeaky wheel gets the grease" seems to be Microsoft’s motto lately, as several patches for Internet Explorer (and components used by IE) were released out-of-cycle last month and on this week’s Patch Tuesday.

Meanwhile, flaws in IE that are equally severe — but were getting less media attention — were left unpatched.


Serious IE ActiveX flaw left unpatched

The so-called SetSlice vulnerability, which had reports of being actively exploited via Internet Explorer, was patched this week with Microsoft’s release of MS06-057 But another IE flaw, which is just as severe, was ignored, perhaps because it wasn’t causing the Redmond company as much trouble.

On Sept. 14, Microsoft released security advisory 925444 to warn customers about a flaw in its DirectAnimation Path ActiveX Control. This advisory stated:

  • “Microsoft is investigating new public reports of vulnerability in Microsoft Internet Explorer on Windows 2000 Service Pack 4, on Windows XP Service Pack 1, and on Windows XP Service Pack 2. Customers who are running Windows Server 2003 and Windows Server 2003 Service Pack 1 in their default configurations, with the Enhanced Security Configuration turned on, are not affected. We are also aware of proof of concept code published publicly and we are aware of limited attacks that are attempting to use the reported vulnerability. Customers would need to visit an attacker’s Web site to be at risk. We will continue to investigate these public reports.

    “The ActiveX control is the Microsoft DirectAnimation Path ActiveX control, which is included in Daxctle.ocx.

    “Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. A security update will be released through our monthly release process or an out-of-cycle security update will be provided, depending on customer needs.”

  • Apparently the “limited attacks,” as they were called, were treated as just that. On Sept. 19, Microsoft released a different security advisory, 926043, involving a flaw in how IE handles VML (Vector Markup Language). This hole was already being exploited in a more widespread fashion. After that, not much more was heard from Microsoft on the issue. The company did update the advisory on Sept. 27, one day after an out-of-cycle patch for the VML flaw was released.

    This article is part of our paid content. Subscribe.

    Already a paid subscriber? Click here to login.

    Related posts:

    1. Microsoft monthly patches
    2. Microsoft security patches
    3. Microsoft warns of unpatched flaw in Internet Explorer
    4. Don’t ignore two critical, reissued patches
    5. More Security Patches
= Paid content

All Windows Secrets articles posted on 2006-10-12:

  • Top Story MS OneCare halts flow of antivirus info
  • Hot Tips You’ll love IE 7′s tabs or hate ‘em
  • Perimeter Scan Is Vista locking out security competitors?
  • Over the Horizon Microsoft skips some critical IE patches
  • Patch Watch Goodbye old friends, hello Office patches
  •  Show all articles on a single page
E-books

We’ve pored through years of back issues, picking the best tips, to create these ebooks:

E-book series
  • PC Maintenance Guide
  • PC Security Guide
  • Windows 7 Guide Vol 1
  • Windows 7 Guide Vol 2
  • Win XP Survival Guide
See the e-book series
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.21
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Don’t pay for software you don’t need — Part 2 4.10
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb