Skip Links

Network World

Julie Bort

Microsoft admits it knew of the IE, zero-day ActiveX hole for months

Patch is "on track" for next Tuesday but MS recommends you don't wait for it

By Microsoft Subnet on Thu, 07/09/09 - 7:45pm.

Microsoft this afternoon responded to accusastions that it knew about a critical IE ActiveX hole for as long as 18 months. The hole is being actively exploited by hackers. To its credit, Microsoft came clean and admitted it did indeed know since the spring of 2008. To its detriment, what's the point of asking researchers to come to you and report under non-disclosure bugs so you can fix them before the hackers find out if you don't fix them until after the hackers find out?

Timeline is this: On Tuesday, Microsoft warned users that the hole existed and that a patch was not available but that the workaround was simple and fairly harmless, to turn the vulnerable service off. Yesterday, researchers came forward to reveal that Microsoft had known about the bug for quite some time. While they didn't reveal the exact date, some detective work by Computerworld reporter Gregg Keizer indicated that the bug was reported to Microsoft in early 2008. Microsoft today confirmed it was reported in spring of 2008.

The following sounds like a defense, but before you flame me, please know that I'm only paraphrasing Microsoft's blog post on the topic and there's more than a little tongue-in-cheek going through my head as I type ... In any case: The excuse was that, as Microsoft was looking into a fix, hackers spontaneously found the bug and started using it. Plus it was a hard (really, really hard) bug to fix as the best fix seemed to be to disable the ActiveX service, which meant testing to ensure that turning it off wouldn't kill anything else. Worth noting that Microsoft had already turned if off in Vista.

If there is any good news to this mess, it is that Microsoft says it will finally have a patch ready and included in next Tuesday's round-o-patches. However, in the ultimate irony, Microsoft also says, don't wait for the patch. Mike Reavey writes in the company's Security Response Center blog:

"Customers who have already implemented the killbits manually or through the FixIt workaround won’t need to implement next week’s security update, though we recommend that you apply the update to ensure that reporting accurately shows that the systems are fully protected. We’re on track to release the security update next Tuesday. But if you haven’t implemented the killbits already, we recommend that you go ahead and do that to protect yourself against the attacks."

Visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)

Follow Microsoft Subnet on Twitter

 

About The Microsoft Update

Julie BortJulie Bort is the editor of Microsoft Subnet and Network World's Online Community Editor. She also writes the Open Source Subnet blog and is the editor responsible for the Cisco Subnet and Open Source Subnet web sites. If you have an idea for a blog, or a news tip on Microsoft, Cisco or Open Source technologies, contact her at jbort@nww.com, 970-482-6454 or follow Julie on Twitter @Julie188.

The Microsoft Subnet blog is the official blog of the Network World's Microsoft Subnet community. Microsoft Subnet is the independent voice of Microsoft customers and is your gateway to daily Microsoft news, blogs, opinion, books, prize giveaways and more. Visit the Microsoft Subnet index page daily, and while you are there, subscribe to the Microsoft newsletter.

Become a Facebook Fan of Julie Bort

Policy on comments: Respectful discussion is welcomed! However comments that use inappropriate language, consist of name calling or personal attacks, or include accusations of wrongdoing are not appropriate. Those comments will be deleted or edited

 

Most Discussed Posts

Blog Roll
Microsoft Subnet Home Page
http://www.networkworld.com/subnets/microsoft/
All Microsoft Subnet bloggers
http://www.networkworld.com/community/blogs/microsoft/feed
ActiveWin
http://www.activewin.com
Blake Handler The Road to Know Where
http://bhandler.spaces.live.com/
Dmitry's PowerBlog
http://dmitrysotnikov.wordpress.com/
Doug Brown,DABCC
http://www.dabcc.com
Ed Bott's Windows Expertise
http://www.edbott.com/weblog/
Joseph Tartakoff Microsoft Blog
http://blog.seattlepi.nwsource.com/microsoft/
Long Zheng istartedsomething
http://www.istartedsomething.com/
Mini-Microsoft
http://minimsft.blogspot.com/
Paul Thurrott's Supersite for Windows
http://www.winsupersite.com
Robert McLaws WindowsNow
http://www.windows-now.com
Scobleizer
http://scobleizer.com/
Techmeme
http://www.techmeme.com/
Todd Bishop's Microsoft Blog
http://www.techflash.com/Microsoft