Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »
Social Responsibility's Strategic Benefits
December 15, 11:30 AM - 12:30 PM US/Eastern (GMT-5)
Join Ed Granger-Happ, CIO of Save the Children, for a discussion of how creating an organization that is socially responsible improves staffing, retention, leadership development and overall corporate health.
Working With and Communicating to Your Board of Directors
January 13, 2009, 4:00 PM - 5:00 PM US/Eastern (GMT-5)
CIO panelists who will share tips and experiences working with their boards: Twila Day of SYSCO; Jeff O'Hare, West Corp.; Marc West, formerly with H&R Block.
IT's Role in Growing Mid-Market Companies
January 14, 4:00 PM - 5:00 PM ET (GMT-5)
Mid-market Council members will share their companies' stories and challenges in driving or coping with growth. Panelists represent Veterinary Pet Insurance, Medicis Pharmaceutical, and Intrax Cultural Exchange.
Learn more about the CIO Executive Council »Apply today for a FREE subscription to CIO Magazine!
July 07, 2008 — IDG News Service —
Cybercriminals are exploiting a bug in software used by Microsoft's Access database program in a new online attack, Microsoft warned Monday.
The flaw lies in the Snapshot Viewer ActiveX control, which ships with "all supported versions of Microsoft Office Access except Microsoft Access 2007," Microsoft said in a security advisory, published Monday.
Microsoft released few details of how the bug is actually being exploited, but said that it is investigating an ongoing computer attack that takes advantage of the problem. "The attack appears to be targeted, and not widespread," wrote Bill Sisk, a Microsoft spokesman, in a blog posting.
Attackers are trying to lure victims to a specially crafted Web page that tries to run the attack code within Internet Explorer. The bug gives attackers a way to run their malicious software on the victim's machine.
Microsoft's Security Advisory offers a number of possible work-arounds for the problem, but the company has not said when it plans to fix the underlying bug.
"We encourage affected customers to implement the manual work-arounds included in the Advisory, which Microsoft has tested," Sisk said. "Although these work-arounds will not correct the underlying vulnerability, they help block known attack vectors."
Snapshot Viewer lets PC users view a Microsoft Access report without having to run the Access software itself. It can be downloaded as stand-alone software.
Because the vulnerable ActiveX control is digitally signed by Microsoft, some users could be attacked even if they haven't installed the Snapshot Viewer control. Victims who have configured Internet Explorer to trust Microsoft software could be forced to silently download the buggy viewer and then be attacked via the Web, said Matthew Richard, director of Verisign's iDefense Rapid Response Team.
Microsoft has made a concerted effort to lock down its core Windows operating system over the past five years and, as a result, hackers have increasingly turned to third-party software and ActiveX components like Snapshot Viewer when looking for bugs.
In April, criminals began using software that included attack code for seven ActiveX bugs, including flaws in controls made by Microsoft, Citrix Systems, Hewlett-Packard, Sony and D-Link.
This latest issue is "another in the long line of ActiveX bugs," said Andrew Storms, director of security operations with nCircle, via instant message. "It's disheartening to see yet another ActiveX problem."
Copyright © 2008 IDG News Service. All rights reserved. IDG News Service is a trademark of International Data Group, Inc.

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.
Over 25 tutorials on everything from business intelligence to virtualization.