Two ActiveX vulnerabilities make IE a toxic choice
Last week Microsoft issued a security advisory warning of an ActiveX vulnerability relating to a video control. There’s no patch in sight. Today we get another advisory relating to another ActiveX control, this time used to display Excel spreadsheets. Since tomorrow is Patch Tuesday, we’re not going to see a patch for this vulnerability either. Both vulnerabilities are being actively targeted by hackers. Is Internet Explorer too toxic to trust?
Microsoft has issued a workaround for both vulnerabilities (here and here) but the number of people who will actively protect themselves from this threat is small, so for the time being there are literally millions of PCs out there wide open to being attacked on two fronts.