Skip to main content

Microsoft Warns of Zero-Day ActiveX Vulnerability in Windows XP

Microsoft Warns of Zero-Day ActiveX Vulnerability in Windows XP

Microsoft has issued a security advisory warning Windows XP users to take immediate steps to protect themselves from an ActiveX security vulnerability that’s already being exploited, particularly in Asia. The problem only impacts Windows XP—which, unfortunately, happens to be one of the most widely-used operating systems on the planet—and would let attackers run arbitrary code as if they were the currently logged-in user. Windows Vista and Windows Server 2008 are not impacted, nor is Windows 2000 SP4. Microsoft is working on a patch; in the meantime, Microsoft is urging users to disable the Microsoft Video ActiveX control from running in Internet Explorer.

The workaround sets a “kill bit” for Microsoft’s Video ActiveX control in the Windows Registry which will prevent Internet Explorer from loading the control. Although it doesn’t eliminate the vulnerability from the system, it does prevent malicious sites from being able to exploit the problem. Microsoft says there are no “by design” uses for the Video ActiveX control in Internet Explorer, so disabling the control shouldn’t have any significant ramifications for users. Microsoft is even recommending Windows Vista and Windows Server 2008 users set the kill bits just in case.

Microsoft has not given a date for when it expects a security patch to be available. The company’s next “Patch Tuesday” update is July 14; a fix might be included in that update, or could be issued separately.

The code for the ActiveX exploit has already been published on a number of Chinese sites.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Microsoft’s dual-screen Windows 10X devices may be delayed to 2022
microsoft surface neo review 3

Microsoft could once again be delaying dual-screen PCs like the Surface Neo, due to changes in the development of the next-generation Windows 10X operating system.

After a previous confirmation of a shift in development that prioritizes single-screen Windows 10X experiences, new rumors hint that  the release for dual-screen variants of Windows 10X has been pushed to spring 2022, according to a report from ZDNet.

Read more
Microsoft to bring Windows 10X to laptops first, pivot from dual screens
microsoft confirms windows 10 x single screen devices b5398ddb6eed22d586aaa3eaf71ff362

Microsoft confirmed previous rumors that it's upcoming Windows 10X operating system once intended for only dual-screen devices, will be coming to laptops and tablets, too.

According to a post penned Panos Panay, the chief product officer of Windows and Devices at Microsoft, the flexibility of Windows 10X has enabled the company to focus its resources "toward single-screen Windows 10X devices that leverage the power of the cloud."

Read more
Report: Microsoft to delay Surface Neo and Windows 10X devices to 2021
Surface Neo

Microsoft is redirecting its energy into optimizing its upcoming Windows 10X operating system for single-screen devices, rather than novel form factors that would have spanned dual-screen and foldables. If the report is accurate, then Microsoft may have just dashed the hopes of Windows faithful who may have hoped to see Microsoft's new dual-screen Surface Neo tablet debut as promised before the end of this year.

Microsoft reporter Mary Jo Foley revealed the findings from contact over at ZDNet. She says that newly installed chief product officer Panos Panay informed his team internally that the Surface Neo and Windows 10X would not ship this calendar year. The delay would also affect third-party dual-screen Windows devices that had planned on shipping this holiday season. So far, we've seen previews of such devices from companies like Dell and Lenovo.

Read more