57
VIEWS
SANS Institute has announced a workaround for the security hole discovered around September 13 that is already being exploited in zero-day attacks. It may be a good option for those who cannot wait for Microsoft’s patch for daxctle.ocx.
Standard Windows Version
(MD5: 599a2e48602f63a5330eea8259216584)
Command-Line Version
(MD5: 571a19cf51f713b81545ebd6a007d792)
When launched, the Windows version displays the current setting of the kill bit for daxctle.ocx and asks whether to turn it ON or OFF. The window title being “Error” is a charming little quirk.
When launched normally, the command-line version turns the kill bit ON; running it with /R clears the setting.
