This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Acer Laptops - ActiveX vuln?

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.f-secure.com/weblog/archives/ar…7.html#00001073
January 9, 2007 ~ "…It's very common that vendors sell machines with preloaded applications and system components of their own. The library, named LunchApp.ocx, is probably supposed to help with browsing the vendor's website, enable easy updates and such – it turns out… it also makes all those machines vulnerable to a specially crafted html file that could instantly download malicious file(s) onto the user's machine and then execute them. It gets even better. Acer enabled "safe for scripting" on that ActiveX library so you wouldn't even see when it's used…"

- http://blog.washingtonpost.com/securityfix…ptop_users.html
January 10, 2007 ~ "Anyone using a laptop made by computer maker Acer Inc. should be aware of a serious security threat apparently resident on many – if not all – models shipped with Microsoft's Windows OS over the past decade or so. According to research first published in November* and picked up only recently by geek** and security news sites, Acer computers ship with a Microsoft ActiveX control that gives bad guys the ability to control any aspect of the computer remotely… It's not clear what function this particular ActiveX (control) has…"

* http://vuln.sg/acerlunchapp-en.html

** http://yro.slashdot.org/article.pl?sid=07/01/08/0515200

:ph34r: