Microsoft rushes out animated cursor security fix


Recommended Posts

Microsoft is to issue an out-of-cycle patch tomorrow for a flaw it revealed last week concerning how Windows treats animated cursor files.

The vulnerability occurs in Windows Vista, Windows 2000 SP4, Windows XP SP2 and some versions of Windows Server 2003.

It can be exploited via email and via websites running the malicious code. Attacks based on the flaw have risen sharply since its discovery last week.

Microsoft had planned to release the patch as part of its monthly update due on 10 April, but the increase in exploits has prompted the firm to release the patch a week early.

Christopher Budd, a security programme manager at Microsoft, said on the company's Security Response Centre Blog: "Over this weekend attacks against this vulnerability have increased somewhat."

"Due to the increased risk to customers, we were able to expedite our testing to ensure an update for broad distribution sooner than 10 April."

Microsoft claimed that the attacks and customer impact are "limited", but is encouraging users to download the patch as soon as it is made available.

Two unofficial patches have already been released to fix the bug, one from eEye Digital Security and one from the Zeroday Emergency Response Team.

Microsoft said that it is working with law enforcement officers to track down attackers.

http://www.vnunet.com/vnunet/news/2186975/...rushes-animated

Just installed it from Windows Update on Windows Vista (Y). And it required a reboot.

http://support.microsoft.com/kb/925902

True, got it an hour ago, wish they would go back to releasing updates as they're ready, so we are protected quicker, seems pointless sometimes having automatic updates set as standard.

Mine was XP Pro only update available can't remember it's KB number.

Most AV apps pick up this "virus". McAfee, at worked, picked it up.

Zert has a test site to check and see if your browser is vulnerable.

http://zert.isotf.org/advisories/zert-2007-01.htm

NOTE: This doesn't seem to affect Firefox.

Most AV apps pick up this "virus". McAfee, at worked, picked it up.

Zert has a test site to check and see if your browser is vulnerable.

http://zert.isotf.org/advisories/zert-2007-01.htm

NOTE: This doesn't seem to affect Firefox.

NOD32 picked it up from the test page too (Y).

So even with UAC and all that stuff, Vista is STILL vulnerable?

One of the articles in the original post says...

Only users running Windows Vista and Internet Explorer 7 in protected mode appear to be safe, according to Microsoft.

In protected mode, no file is allowed to access or modify any system files without user permission.

Sounds like a COMBO thing. Vista AND IE7 in protected mode. Is IE7 in protected mode by default on Vista?

If that were the case that Vista alone was unable to be harmed by it, why would they release a patch for Vista?

Yes UAC and IE7 protected mode (needs UAC enabled) are default, so most Vista users were immune to this threat. UAC is already holding its worth. Why I have it on and I'm a pretty knowledgeable computer user.

Sounds like a COMBO thing. Vista AND IE7 in protected mode. Is IE7 in protected mode by default on Vista?

If that were the case that Vista alone was unable to be harmed by it, why would they release a patch for Vista?

Because not everyone is running in protected mode.. some corporate/business apps have issues.

And they need to fix the bug... damned if they do, damned if they don't!

This patch killed my WMP. Everytime I try and open it, it stops responding! I uninstalled the patch, didn't help. System restore didn't help either. Is anyone else experiencing this issue? I heard many people are having trouble with this patch.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • "This transition will take several years so we shouldn't bother doing it at all" is a naive take. This is completely normal for all specifications that cross-cut software, hardware and multiple industries. Look at the PCI specification for another example, consumers barely have PCI-E 5 yet PCI-SIG is working on PCI-E 8. AV2 will take multiple years to get adoption and even then, even a decade from now people will still have older hardware that doesn't support it. That's fine, because the savings still add up as newer devices add the hardware to deal with it. The goal is never to get 100% on the new spec overnight, but to gradually adopt it.
    • Firefox, and Vivaldi for the rare instances I need a Chrome based browser for a particular site.
    • I named Hitler because he is the de facto anti-semite. But you don't have to hate Jews to be a genocidal maniac. In fact, these days, so called semites are the ones acting in ways that would make Hitler proud.
    • 3DP Chip 26.05 by Razvan Serea 3DP Chip is a standalone, no-install portable tool that scans your computer’s hardware and automatically detects the latest drivers available for your specific configuration and external devices. It provides a clear list of drivers that need updates, locates the correct downloads, and helps you upgrade them easily. 3DP Chip will automatically detect and display the information on your CPU, motherboard, video card and sound card installed on your PC. You can also choose to copy these information into your clipboard with one click for later use (such as posting in a forum). Also, if you're upgrading your operating system or just need to reinstall Windows, 3DP Chip can backup all the drivers on your PC or laptop. 3DP Chip backup and reinstall features can save you hours of searching for and installing individual device drivers. 3DP Chip most popular drivers include: audio and sound drivers video drivers printer and scanner drivers digital camera drivers network drivers webcam drivers keyboard and mouse drivers 3DP Chip v26.05 changelog: Driver date/version information has been added or updated AMD motherboard chipset v8.03.25.247 AMD motherboard chipset v8.05.04.516 Newly added product or support has been enhanced AMD Radeon Graphics AMD Radeon 780M Graphics AMD Radeon 840M Graphics AMD Radeon 860M Graphics AMD Radeon 880M Graphics AMD Radeon RX 9070 XT AMD Radeon Pro W7500M NVIDIA GeForce RTX 3050 6GB Laptop GPU NVIDIA GeForce RTX 4050 Laptop GPU NVIDIA GeForce RTX 5050 Laptop GPU NVIDIA GeForce RTX 5050 Laptop GPU NVIDIA GeForce RTX 5060 NVIDIA GeForce RTX 5070 Laptop GPU NVIDIA GeForce RTX 5070 Ti Laptop GPU NVIDIA RTX Pro 500 Blackwell Generation Laptop GPU NVIDIA RTX Pro 1000 Blackwell Generation Laptop GPU NVIDIA RTX Pro 2000 Blackwell Generation Laptop GPU Download: 3DP Chip 26.05 | 7.2 MB (Freeware) Links: 3DP Chip Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      nothanks earned a badge
      One Month Later
    • One Month Later
      B2Proxy earned a badge
      One Month Later
    • One Year In
      MadMung0 earned a badge
      One Year In
    • Week One Done
      jefred earned a badge
      Week One Done
    • Apprentice
      JoeyNeo went up a rank
      Apprentice
  • Popular Contributors

    1. 1
      +primortal
      472
    2. 2
      PsYcHoKiLLa
      229
    3. 3
      Skyfrog
      72
    4. 4
      FloatingFatMan
      62
    5. 5
      neufuse
      53
  • Tell a friend

    Love Neowin? Tell a friend!