
The US-CERT is urging Web surfers to immediately disable ActiveX controls from Internet Explorer to protect against a swath of publicly reported--and unpatched--software vulnerabilities.
The US-CERT (Computer Emergency Response Team) recommendation follows the release of <A HREF="http://www.eweek.com/c/a/Security/ActiveX-Under-Seige-Facebook-MySpace-Image-Uploaders-Vulnerable/?kc=EWKNLNAV020508STR1">exploit code for multiple zero-day flaws</A> in image uploaders used by Facebook and MySpace and bugs in the ActiveX control that ships with the Yahoo Music Jukebox software.
The exploits, posted to the Milw0rm.com Web site, provides a roadmap for full remote code execution attacks on Windows computers.