Aug 15, 2008

Microsoft Sets Kill Bits

At the request of their ISVs, Microsoft has released kill bit packages for certain versions of HP Instant Support and Aurigma Image Uploader. They have been released as part of a cumulative security update for ActiveX with many other kill bits.

Kill bits are settings in the Windows registry which disable an ActiveX control. When an ISV finds a vulnerability in an ActiveX control they often ask Microsoft to disable that control by making the kill bit available. Click here to learn more about kill bits.

This cumulative update was pushed out with this past Patch Tuesday's set of updates, but the update was rated Important, so if your Automatic Updates is set only to apply critical updates you may not have it.

You can apply the update by running Windows Update manually or by downloading and running the appropriate update for your system from Microsoft's Knowledge Base.

For details on the new kill bits and what they kill see the advisories at Aurigma and HP (here and here).

Excerpt: A cumulative update disables many faulty ActiveX controls.

(full story)