| Home > Special Alert |
| eBay Enhanced Picture Services ActiveX Control Update |
|
Why is there an update? A vulnerability was found in the eBay Enhanced Picture Services ActiveX control used before January 2009. By convincing a user to view a malicious web page, an attacker may have been able to execute arbitrary code on the user's system via this vulnerability. Getting the update Sellers will be automatically prompted to receive the new ActiveX control if they go through any eBay flows that use the eBay Enhanced Picture Services ActiveX control. Microsoft will also bundle a patch into their monthly security update, beginning in June, that will prevent the old vulnerable ActiveX control from being used or abused. Who might have been affected? Users who installed the eBay Enhanced Picture Services ActiveX control prior to January 2009 would have received the vulnerable version. The ActiveX control exists in the following flows and products:
|