PDF problem only part of larger Windows security hole
It turns out that the PDF reader ActiveX security hole mentioned earlier is only part of the problem. The real problem is with Windows XP and IE7. Ryan Naraine at ZDNet reports:
In the wake of this week’s malware attacks using rigged PDF files, Microsoft has updated its security advisory to stress that the underlying flaw — in the Windows operating system — is still not fixed.
The advisory, first issued on October 10, points to an unpatched code execution hole in Windows XP and Windows Server 2003 (with Windows Internet Explorer 7 installed). While applications like Adobe Reader/Acrobat are currently being used as the vector for attack, Microsoft is making it clear that patches from third-party vendors aren’t a cure-all for this bug.
When might a fix be forthcoming? Microsoft is mum.