Welcome | Sign In
ECommerceTimes.com
Security

ActiveX Compatibility at Center of Patch Tuesday

Print Version
E-Mail Article
Reprints
ActiveX Compatibility at Center of Patch Tuesday

"This could be a pretty painful update with regard to ActiveX. It does mean going back in making adjustments to code," Rob Enderle, principal at The Enderle Group, told TechNewsWorld. "There has been an increasing resistance to use ActiveX at all because of the exposure, so the update might not be as widespread. It will be painful, though, for those who have to make the adjustment. There is no easy way around it."


eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.

Microsoft's (Nasdaq: MSFT) scheduled monthly Patch Tuesday is rolling around again on June 13. This round will include updates to the Windows operating system and the controversial ActiveX.

The release will feature nine Microsoft Security Bulletins affecting Microsoft Windows, at least one of which is critical. Another patch will change the way Internet Explorer handles ActiveX controls in response to the ongoing Eolas patent infringement suit.

ActiveX is a technology developed by Microsoft for use with browsers. ActiveX is based on reusable software components that can interact with one another, especially in a networked environment. ActiveX components can be written in any of a number of programming languages. The technology is the basis for creating the ActiveX controls often used to customize and add interactivity to Web pages.

Painful Patch

Microsoft issued a compatibility patch in April to give developers an adjustment period for the new method of handling controls, but the compatibility bridge will cease with this month's patches. All users who apply the June 13 security update will receive the ActiveX update regardless of whether or not they have applied the compatibility patch.

"This could be a pretty painful update with regard to ActiveX. It does mean going back in making adjustments to code," Rob Enderle, principal at The Enderle Group, told TechNewsWorld. "There has been an increasing resistance to use ActiveX at all because of the exposure, so the update might not be as widespread. It will be painful, though, for those who have to make the adjustment. There is no easy way around it."

Legal Wranglings

Unlike most Patch Tuesdays, June 13 is characterized by legal wranglings. Eolas sued Microsoft in February 1999 for patent infringement. Eolas initially won the suit and Microsoft was ordered to pay US$521 million to the company.

Microsoft appealed and had the decision reversed in 2005. Microsoft has maintained throughout the process that the Eolas patent is not valid and that the enforcement of the patent further created confusion that could have impacted the use of the World Wide Web.

This concern was shared by others in the industry -- including the W3C -- who have also maintained that the patent is invalid and have requested a re-examination by the U.S. Patent Office. Seven years later, the suit is still not settled but Microsoft is moving ahead to make changes to ActiveX controls.

Less Critical Vulnerabilities

Microsoft is also issuing a Security Bulletin affecting Microsoft Exchange. Users cannot send an e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse message in Microsoft Exchange 2000 Server on in Microsoft Exchange Server 2003. Users may also receive an error message indicating that access is denied or that they do not have sufficient permission to perform the operation. The vulnerability is rated as "important."

Microsoft will release two "critical" bulletins affecting Office. The software giant did not release additional details about this update, but added that it would release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Service and the Download Center.

Microsoft will also release one non-security high-priority update for Windows and two non-security high-priority updates on Microsoft Update and Windows Server Update Services. "IT departments are getting used to the fact that they will be asked to patch at a fairly high rate and have been updating their processes to do that for a while," Enderle said. "It's unfortunate, but it's the reality we live in."


Print Version E-Mail Article Reprints More by Jennifer LeClaire


Related News Alerts

Microsoft Activate Alert | Search Archives

More by Jennifer LeClaire

The Digital Car: Cool Automotive Accessories, Part 2
January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers
January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand
January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network