Microsoft rushes out animated cursor security fix


Recommended Posts

Microsoft is to issue an out-of-cycle patch tomorrow for a flaw it revealed last week concerning how Windows treats animated cursor files.

The vulnerability occurs in Windows Vista, Windows 2000 SP4, Windows XP SP2 and some versions of Windows Server 2003.

It can be exploited via email and via websites running the malicious code. Attacks based on the flaw have risen sharply since its discovery last week.

Microsoft had planned to release the patch as part of its monthly update due on 10 April, but the increase in exploits has prompted the firm to release the patch a week early.

Christopher Budd, a security programme manager at Microsoft, said on the company's Security Response Centre Blog: "Over this weekend attacks against this vulnerability have increased somewhat."

"Due to the increased risk to customers, we were able to expedite our testing to ensure an update for broad distribution sooner than 10 April."

Microsoft claimed that the attacks and customer impact are "limited", but is encouraging users to download the patch as soon as it is made available.

Two unofficial patches have already been released to fix the bug, one from eEye Digital Security and one from the Zeroday Emergency Response Team.

Microsoft said that it is working with law enforcement officers to track down attackers.

http://www.vnunet.com/vnunet/news/2186975/...rushes-animated

Just installed it from Windows Update on Windows Vista (Y). And it required a reboot.

http://support.microsoft.com/kb/925902

True, got it an hour ago, wish they would go back to releasing updates as they're ready, so we are protected quicker, seems pointless sometimes having automatic updates set as standard.

Mine was XP Pro only update available can't remember it's KB number.

Most AV apps pick up this "virus". McAfee, at worked, picked it up.

Zert has a test site to check and see if your browser is vulnerable.

http://zert.isotf.org/advisories/zert-2007-01.htm

NOTE: This doesn't seem to affect Firefox.

Most AV apps pick up this "virus". McAfee, at worked, picked it up.

Zert has a test site to check and see if your browser is vulnerable.

http://zert.isotf.org/advisories/zert-2007-01.htm

NOTE: This doesn't seem to affect Firefox.

NOD32 picked it up from the test page too (Y).

So even with UAC and all that stuff, Vista is STILL vulnerable?

One of the articles in the original post says...

Only users running Windows Vista and Internet Explorer 7 in protected mode appear to be safe, according to Microsoft.

In protected mode, no file is allowed to access or modify any system files without user permission.

Sounds like a COMBO thing. Vista AND IE7 in protected mode. Is IE7 in protected mode by default on Vista?

If that were the case that Vista alone was unable to be harmed by it, why would they release a patch for Vista?

Yes UAC and IE7 protected mode (needs UAC enabled) are default, so most Vista users were immune to this threat. UAC is already holding its worth. Why I have it on and I'm a pretty knowledgeable computer user.

Sounds like a COMBO thing. Vista AND IE7 in protected mode. Is IE7 in protected mode by default on Vista?

If that were the case that Vista alone was unable to be harmed by it, why would they release a patch for Vista?

Because not everyone is running in protected mode.. some corporate/business apps have issues.

And they need to fix the bug... damned if they do, damned if they don't!

This patch killed my WMP. Everytime I try and open it, it stops responding! I uninstalled the patch, didn't help. System restore didn't help either. Is anyone else experiencing this issue? I heard many people are having trouble with this patch.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I found that stability back then was really down to the motherboard manufacturer. Back then i stuck with Microstar motherboards and VIA chipsets as they were ultra reliable. Most stuff was done with jumpers and left little room for user created problems 👍
    • Yes, Scoop was created to promote Coreutils for Windows. You can still see early versions of their website on the Web Archive. It was a joke that nobody took seriously. Microsoft's implementation of Coreutils, however, are built in Rust.
    • Looks like EA's Star Wars Zero Company will be out this August by Pulasthi Ariyasinghe Over a year ago, EA surprise announced that a team of former Firaxis members is working on a brand-new Star Wars game. Dubbed Zero Company, the title would have XCOM-like turn-based tactics gameplay as players manage a squad of professionals from all over the galaxy. Now, just ahead of an official announcement, it looks like the release date has leaked out. The upcoming Summer Game Fest presentation on Friday is when EA is supposed to show off the title's gameplay footage, with fans also expecting it to reveal a release date. However, the ever-reliable billbil-kun from Dealabs says they have already managed to find out when the game is coming out and what versions fans will have the option of purchasing. Per the leak, Star Wars Zero Company has an August 27, 2026, release date attached to it. The title is slated to release on PC, Xbox Series X|S, and PlayStation 5 with a $49.99 standard and $59.99 Deluxe edition. The leaker also adds that there won't be any early access perk attached to this special edition. Pre-orders could kick off alongside the official announcement this Friday, too. For those unfamiliar with the title, Bit Reactor is developing Star Wars Zero Company with help from Respawn Entertainment and Lucasfilm Games. The EA-published title is said to be set during the "twilight of the Clone Wars." We will have to wait and see if base building and management mechanics from the XCOM series will be present here, too. "You will step into the shoes of Hawks, a former Republic officer who leads Zero Company — an unconventional outfit of professionals for hire hailing from across the galaxy," reads the game description. "Hawks and Zero Company are recruited for an operation that pits them against an emerging threat that will consume the galaxy if left unchecked. To succeed, Hawks will lead a team of uneasy allies who must set aside their differences to overcome nearly impossible odds." You can catch the Star Wars Zero Company extended gameplay reveal at the Summer Game Fest showcase that's kicking off on Friday at 2 pm PT / 5 pm ET.
    • All their other games always had a new cast and new story, so that's not very surprising. The new dev is worrisome though.
  • Recent Achievements

    • One Month Later
      nothanks earned a badge
      One Month Later
    • One Month Later
      B2Proxy earned a badge
      One Month Later
    • One Year In
      MadMung0 earned a badge
      One Year In
    • Week One Done
      jefred earned a badge
      Week One Done
    • Apprentice
      JoeyNeo went up a rank
      Apprentice
  • Popular Contributors

    1. 1
      +primortal
      490
    2. 2
      PsYcHoKiLLa
      234
    3. 3
      Skyfrog
      78
    4. 4
      FloatingFatMan
      68
    5. 5
      Michael Scrip
      58
  • Tell a friend

    Love Neowin? Tell a friend!