News

Microsoft Postpones ActiveX Fix for Internet Explorer

Microsoft indicated it will postpone a planned fix for Internet Explorer to block out-of-date ActiveX controls because of customer feedback, apparently to give users more time for testing.

It will now be Sept. 9 before the new security protection feature for Internet Explorer that blocks older installations of ActiveX takes effect, instead of today as announced earlier. Also, the fix will only block Oracle Java ActiveX for now.

The "out-of-date ActiveX control blocking" security feature was still scheduled to be part of today's update to IE browsers, but the new blocking feature won't take effect for another month, states an addendum to Microsoft's original announcement. Posted on Sunday, it reads as follows:

Based on customer feedback, we have decided to wait thirty days before blocking any out-of-date ActiveX controls. Customers can use the new logging feature to assess ActiveX controls in their environment and deploy Group Policies to enforce blocking, turn off blocking ActiveX controls for specific domains, or turn off the feature entirely depending on their needs. The feature and related Group Policies will still be available on August 12, but no out-of-date ActiveX controls will be blocked until Tuesday, September 9th. Microsoft will continue to create a more secure browser, and we encourage all customers to upgrade and stay up-to-date with the latest Internet Explorer and updates.

It's not exactly clear what customer feedback caused Microsoft to delay the out-of-date ActiveX blocking, although an updated FAQ accompanying Microsoft's original announcement stated that it was done "in order to give customers time to test and manage their environments."

One new addition to the FAQ explains that the out-of-date ActiveX control blocking feature will become available for IE browsers through the "August Internet Explorer Cumulative Security Update" scheduled for today, which likely means that it will arrive as part of Microsoft's general patch Tuesday security bulletin release, rather than as a separate download. Microsoft keeps a list of outdated ActiveX controls in a file called "versionlist.xml." That versionlist.xml file will be downloaded by IE browsers "within 12 hours of installing the August Cumulative Update and starting Internet Explorer."

Another new piece of information that was added to Microsoft's FAQ is that "only out-of-date Oracle Java ActiveX controls will be blocked by this feature" in September. However, Microsoft plans to consider blocking other out-of-date ActiveX controls in its future IE update releases.

Microsoft's technical documentation about the new blocking capability still seems to be somewhat thin at this date. However, Microsoft indicated it's planning to release new TechNet documentation and Group Policy administrative templates today.

In addition to using four new Group Policy additions or administrative templates to manage the ActiveX blocking feature, it's possible to disable it for specific domains or disable it entirely by making some Registry changes. Microsoft's amended FAQ lists the Registry settings to make in such cases.

About the Author

Kurt Mackie is senior news producer for 1105 Media's Converge360 group.

comments powered by Disqus

Featured

  • How to Unlock Visual Studio 2022's Preview Features Like Claude Sonnet 3.7 AI Model

    Some developers complained that advanced AI models come sooner to VS Code than Visual Studio, but the new Claude Sonnet 3.7 model is now available in IDE with a paid GitHub Copilot account and a simple settings tweak in GitHub.

  • Semantic Kernel Agent Framework Graduates to Release Candidate

    With agentic AI now firmly established as a key component of modern software development, Microsoft graduated its Semantic Kernel Agent Framework to Release Candidate 1 status.

  • TypeScript 5.8 Improves Type Checking, Conditional Feature Delayed to 5.9

    Microsoft shipped TypeScript 5.8 with improved type checking in some scenarios, but thorny problems caused the dev team to delay related work to the next release.

  • Poisson Regression Using C#

    Dr. James McCaffrey from Microsoft Research presents a complete end-to-end demo of Poisson regression, where the goal is to predict a count of things arriving, such as the number of telephone calls received in a 10-minute interval at a call center. When your source data is close to mathematically Poisson distributed, Poisson regression is simple and effective.

  • Cloud-Focused .NET Aspire 9.1 Released

    Along with .NET 10 Preview 1, Microsoft released.NET Aspire 9.1, the latest update to its opinionated, cloud-ready stack for building resilient, observable, and configurable cloud-native applications with .NET.

Subscribe on YouTube

Upcoming Training Events