Microsoft Warns Of Third 'Browse-And-Get-Owned' Flaw
Despite moving aggressively to fix zero-day vulnerabilities in its software, Microsoft will have to move faster still to keep up with criminal hackers. One day before the company plans to release its July patch and fix two "browser-and-get-owned" vulnerabilities, a third "browse-and-get owned" flaw has been reported.
On Monday, Microsoft issued a Security Advisory about a previously undisclosed vulnerability in Office Web Components Spreadsheet ActiveX control (OWC 10 and OWC11).
"The vulnerability exists specifically in the Spreadsheet ActiveX Control and could allow an attacker who successfully exploited this vulnerability the same user rights as the local user," the Microsoft advisory states. "We are aware of limited, active attacks attempting to exploit this vulnerability."