On Thursday, July 02, 2009, symantec became aware of a previously-un-known Vulnerability Affecting Microsoft Windows. This Issue Affects the msvidctl.dll Video Streaming ActiveX Control. Attackers can Exploit the Issue to Execute Arbitrary Code by Enticing a Vulnerable User to Visit a Malicious Web Site. This Issue is being Exploited in-the-Wild in Limited Attacks. Currently, we are not aware of any Patches for this Vulnerability.
Users are advised to:
- Use Caution while Accessing Un-Trusted Web Sites.
- Avoid following Web Links that Originate from Un-Known Sources.
- Consider setting the Kill-Bit on the associated C.L.S.I.D..
- Deploy Script-Blocking Mechanisms in the Browser.
- Deploy Memory-Protection Schemes such as Non-Executable Stack/Heap Configurations and Randomly-Mapped Memory Segments.