Microsoft warns of new Access attack
Cybercriminals are exploiting a bug in software used by Microsoft's Access database programme in a new online attack, Microsoft warned Monday. The flaw lies in the Snapshot Viewer ActiveX control, which ships with "all supported versions of Microsoft Office Access except Microsoft Access 2007," Microsoft said in a security advisory, published Monday.
Microsoft released few details of how the bug is actually being exploited, but said that it is investigating an ongoing computer attack that takes advantage of the problem. "The attack appears to be targeted, and not widespread," wrote Bill Sisk, a Microsoft spokesman, in a blog posting.
Attackers are trying to lure victims to a specially crafted Web page that tries to run the attack code within Internet Explorer. The bug gives attackers a way to run their malicious software on the victim's machine. Microsoft's Security Advisory offers a number of possible work-arounds for the problem, but the company has not said when it plans to fix the underlying bug.