Mobile // Mobile Devices
05:14 PM
Connect Directly
Repost This

RIM Issues BlackBerry Security Advisory

Vulnerabilities in the BlackBerry Application Web Loader ActiveX control could allow an attacker to execute code remotely or cause Microsoft Internet Explorer to crash.

Research In Motion (RIM) on Tuesday issued a security advisory to those of its BlackBerry customers who are using BlackBerry Application Web Loader Version 1.0 and Microsoft Internet Explorer.

A vulnerability in the BlackBerry Application Web Loader ActiveX control could allow an attacker to execute code remotely or to cause Microsoft Internet Explorer to crash, the company said.

"An exploitable buffer overflow exists in the BlackBerry Application Web Loader ActiveX control that Internet Explorer uses to install applications on BlackBerry devices," RIM explains in its advisory. "When a BlackBerry device user browses to a Web site that is designed to install the BlackBerry Application Web Loader ActiveX control on BlackBerry devices over a USB connection, and clicks 'Yes' to install and run the ActiveX control, the ActiveX control introduces the vulnerability to the computer."

RIM's warning comes in conjunction with a security advisory issued by Microsoft that updates its ActiveX kill bit list to include a kill bit to prevent the BlackBerry Application Web Loader ActiveX control from being exploited.

The vulnerability can be resolved by installing an updated version of the BlackBerry Application Web Loader. The RIM Web site also includes a workaround that describes how to disable the affected ActiveX control.

In its 2008 X-Force Trend and Risk report, released earlier this month, IBM reports that ActiveX controls accounted for 46% of all browser-related vulnerability disclosures in 2008, and 66% of browser-related vulnerabilities designated "critical" or "high."

There was an overall decline in browser-related vulnerability disclosures last year, according to IBM's report.

"Unfortunately, the decline in ActiveX disclosures does not appear to be making an impact on exploitation," the report said. "As with other browser-related vulnerabilities, attackers rely upon users who do not keep their browsers current. Although Microsoft has made great strides in preventing ActiveX exploitation through changes to Microsoft Internet Explorer, exploitation remains an issue along with the continued usage of known vulnerable ActiveX controls from non-malicious Web sites."

InformationWeek has published an independent analysis of what other security measures companies can take for their mobile workforces. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Building A Mobile Business Mindset
Building A Mobile Business Mindset
Among 688 respondents, 46% have deployed mobile apps, with an additional 24% planning to in the next year. Soon all apps will look like mobile apps and it's past time for those with no plans to get cracking.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Elite 100 - 2014
Our InformationWeek Elite 100 issue -- our 26th ranking of technology innovators -- shines a spotlight on businesses that are succeeding because of their digital strategies. We take a close at look at the top five companies in this year's ranking and the eight winners of our Business Innovation awards, and offer 20 great ideas that you can use in your company. We also provide a ranked list of our Elite 100 innovators.
Twitter Feed
Audio Interviews
Archived Audio Interviews
GE is a leader in combining connected devices and advanced analytics in pursuit of practical goals like less downtime, lower operating costs, and higher throughput. At GIO Power & Water, CIO Jim Fowler is part of the team exploring how to apply these techniques to some of the world's essential infrastructure, from power plants to water treatment systems. Join us, and bring your questions, as we talk about what's ahead.