Shavlik Responds to New Microsoft Zero Day Video ActiveX Control Exploit
Current Shavlik Customers Are Protected
ST. PAUL, Minn.--(BUSINESS WIRE)--Shavlik Technologies, LLC, the market leader in simplifying and automating critical-to-perform IT operational tasks, today issued the following commentary in response to Microsoft's Security Advisory 972890 which addresses a new vulnerability in a Microsoft Video ActiveX Control affecting Windows XP and Windows Server 2003 that could allow remote code execution if a user browses to a malicious Web page.
"There are reports that there are an increasing number of affected websites which could be serving up this exploit to millions of unsuspecting users. Since the control doesn’t serve any purpose within Internet Explorer, we agree with Microsoft’s recommendation to set this kill bit immediately," said Eric Schultze, CTO, Shavlik Technologies. "Corporations and some end-users may be protected via their anti-virus solutions, depending on the solution they are using."
Shavlik’s suite of solutions offers workarounds that disable the Microsoft Video ActiveX Control from running in Internet Explorer. Shavlik offers two options to automate and simplify the process to disabling the ActiveX control:
Shavlik NetChk Protect – the policy is already included in NetChk Protect, and offers the flexibility to quickly deploy the “Microsoft Fix It” tool workaround to disable the ActiveX control, using either an agent or agent-based architecture to meet the needs of the enterprise.
Shavlik NetChk Configure – a special policy using custom checks has been created by Shavlik that changes the specific registry settings (i.e. kill bits) to protect against known exploit code. This special policy is available at for download and import into NetChk Configure.
Shavlik is making these solutions available on its web site at www.shavlik.com.
About Shavlik Technologies
Shavlik Technologies, LLC is the market leader for simplifying and automating critical-to-perform and manage IT operations including patch management, antivirus + antispyware, configuration management, and policy and compliance auditing. Shavlik’s innovative approach to simplifying and automating management of the platform frees up IT staff for initiatives that grow your business without sacrificing the visibility and control needed to ensure system uptime and demonstrate proof of compliance with internal policies and external regulations.
With more than 10,000 customers worldwide, Shavlik is trusted to provide solutions that can be relied upon to identify gaps and automatically and reliably fix systems that are missing patches or don't conform with the corporate-defined configuration baseline. More information can be found at www.shavlik.com.
Shavlik Technologies is a registered trademark in the United States and certain other countries, of Shavlik Technologies. Additional Shavlik product names are either registered trademarks or trademarks of Shavlik Technologies. All other trademarks mentioned in this document are the property of their respective owners.
