If you use an Acer PC or laptop you might want to check for a security loophole in your machine’s version of Windows that a truck could run through sideways. A November 2006 Web article authored by someone named Tan Chew Keong in Singapore (also reported by Slashdot) finds that Acer have put an ActiveX control, LunchApp.APlunch, on their machines that is marked “safe for scripting” and “safe for initializing from persistent data”. Given the features of this OCX it means that any Web page loaded by IE6 or below can, in theory, launch any application. IE7 prevents this behavior although it can also be configured to allow it! This OCX is dated 1998 and has only confirmed to exist on Singapore models so we have no idea if this is a problem on machines sold in the rest of the world. If you own an Acer machine and you’re not in Singapore search for LunchApp.APlunch and let me know if it exists.
Acer Users Beware!
Opinion
Jan 8, 20071 min




