http://www.juiceapac.com/solutions

Microsoft warns of new Access attack PDF Print E-mail
Cybercriminals are exploiting a bug in software used by Microsoft Corp.'s Access database program in a new online attack, the company warned today.

The flaw lies in the Snapshot Viewer ActiveX control, which ships with "all supported versions of Microsoft Office Access except Microsoft Access 2007," the software maker said in a security advisory.

Microsoft released few details of how the bug is being exploited but said that it is investigating an ongoing computer attack that takes advantage of the problem. "The attack appears to be targeted, and not widespread," wrote Bill Sisk, a Microsoft spokesman, in a blog post.

Attackers are trying to lure victims to a specially crafted Web page that tries to run the attack code within Internet Explorer. The bug gives attackers a way to run their malicious software on the victim's machine.

Microsoft's advisory offers a number of possible work-arounds for the problem, but the company has not said when it plans to fix the underlying bug.

"We encourage affected customers to implement the manual work-arounds included in the Advisory, which Microsoft has tested," Sisk wrote. "Although these work-arounds will not correct the underlying vulnerability, they help block known attack vectors."

Snapshot Viewer lets PC users view a Microsoft Access report without having to run the Access software itself. It can be downloaded as stand-alone software.

 
< Prev   Next >