Microsoft Windows Knowledge Base Article 948881 update not installed (WinMs08kb948881Update)

Vuln ID: 41465
Risk Level: High risk vulnerability  High WinMs08kb948881Update
Platforms: Microsoft Windows Vista: SP1, Microsoft Windows 2008: x64, Microsoft Windows 2008, Microsoft Windows Vista: SP1 x64, Microsoft Windows 2008: Itanium, Microsoft Windows Vista, Microsoft Windows XP: SP2 Professional x64, Microsoft Windows Vista: x64, Microsoft Windows 2003 Server: SP2 x64, Microsoft Windows 2003 Server: SP2 Itanium, Microsoft Windows 2003 Server: SP2, Microsoft Windows 2003 Server: SP1, Microsoft Windows 2003 Server: SP1 Itanium, Microsoft Windows XP: Professional x64, Microsoft Windows XP: SP2, Microsoft Windows 2003 Server: x64, Microsoft Internet Explorer: 6 SP1, Microsoft Windows 2000: SP4, Microsoft Internet Explorer: 5.01 SP4
Description:

Microsoft Windows Knowledge Base Article 948881 update is not installed on the system, which could allow an attacker to exploit the following vulnerability:

Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on the system, caused by a vulnerability that occurs when Internet Explorer attempts to instantiate the hxvz.dll object as an ActiveX control. By persuading a victim to visit a malicious Web page containing an invalid object, a remote attacker could exploit this vulnerability to corrupt memory and execute arbitrary code on the system or cause the application to crash.

Remedy:

Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS08-023. See References.

False Positives:
False Negatives:
Required Permission: Windows login
Additional Information:

References:

Microsoft Security Bulletin MS08-023
Security Update of ActiveX Kill Bits (948881)
http://www.microsoft.com/technet/security/bulletin/ms08-023.mspx

IBM Internet Security Systems X-Force Database
Microsoft Internet Explorer hxvz.dll object code execution
http://xforce.iss.net/xforce/xfdb/41464

ISS X-Force
Microsoft Windows Knowledge Base Article 948881 update not installed
http://www.iss.net/security_center/static/41465.php

CVE CVE-2008-1086
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1086


X-Force Logo
Know Your Risks
Mitre.org CVE Logo
Common Vulnerabilties & Exposures