Sneaky Microsoft plug-in puts Firefox users at risk


Recommended Posts

Sneaky Microsoft plug-in puts Firefox users at risk

An add-on that Microsoft silently slipped into Mozilla's Firefox last February leaves that browser open to attack, Microsoft's security engineers acknowledged earlier this week.

One of the 13 security bulletins Microsoft released Tuesday affects not only Internet Explorer (IE), but also Firefox, thanks to a Microsoft-made plug-in pushed to Firefox users eight months ago in an update delivered via Windows Update.

"While the vulnerability is in an IE component, there is an attack vector for Firefox users as well," admitted Microsoft engineers in a post to the company's Security Research & Defense blog on Tuesday. "The reason is that .NET Framework 3.5 SP1 installs a 'Windows Presentation Foundation' plug-in in Firefox."

For the rest of the article

http://news.idg.no/cw/art.cfm?id=5CF0A4A7-...45F5A54F2136086

Consider that add-on uninstalled from my system. Idiots.

I just got the notice from Firefox today. Said the Microsoft.NET Framework Assistant and Windows Presentation Foundation would cause instability and you know what, I have noticed some hanging the last day or so with Firefox open that I never noticed before. Could be related or maybe not. Will see if the issue pops up again.

How do you remove plugins from the blocklist?

EDIT: Fixed. I had to turn off extensions.blocklist.enabled in about:config and reinstall the framework assistant. (Mozilla removed it from their repository. I found it here: http://mirror.atlanticmetro.net/mozilla/addons/9449/)

Do NOT block things on my computer without permission or a way to re-enable them, Mozilla.

Edited by GreyWolfSC
Probably.

It was also a .NET Framework 3.5 plugin getting installed on firefox anyway.

pretty much,yes

How do you remove plugins from the blocklist?

EDIT: Fixed. I had to turn off extensions.blocklist.enabled in about:config and reinstall the framework assistant. (Mozilla removed it from their repository. I found it here: http://mirror.atlanticmetro.net/mozilla/addons/9449/)

Do NOT block things on my computer without permission or a way to re-enable them, Mozilla.

your link is broken , remove the ")" from the end of the link

:)

I just got the notice from Firefox today. Said the Microsoft.NET Framework Assistant and Windows Presentation Foundation would cause instability and you know what, I have noticed some hanging the last day or so with Firefox open that I never noticed before. Could be related or maybe not. Will see if the issue pops up again.

same here, and also noticed my Firefox hanging recently. I'd prefer no Firefox secret installations from Microsoft if they are reading this ...

same here, and also noticed my Firefox hanging recently. I'd prefer no Firefox secret installations from Microsoft if they are reading this ...

It's not a secret Firefox installation. The plug-in is installed as part of the .NET Framework and Firefox picks it up automatically. If anything, we should complain to Mozilla for the browser not asking if the "found" plugin should be added. Their methodology could easily activate a hidden malware plugin the same way.

Strangely this morning when I turned my monitor on (My PC is on constantly) I had a warning from Firefox that it had disabled the Windows Foundation plugin (when checking the plugins it just says "known to cause security issues") and it directed me to the webpage https://en-gb.www.mozilla.com/en-GB/blocklist/

I just got the notice from Firefox today. Said the Microsoft.NET Framework Assistant and Windows Presentation Foundation would cause instability and you know what, I have noticed some hanging the last day or so with Firefox open that I never noticed before. Could be related or maybe not. Will see if the issue pops up again.

I got the message yesterday as well, right before firefox crashed on me. :no:

Mozilla is in your browser, disabling your addons ;)

screw that sh*t

its been all over the net how to disable/remove this Microsoft addon long before they enabled the option

i do not need Mozilla looking out for me

That's what I'm sayin'. I bet Mozilla wouldn't have liked it if Microsoft had uninstalled and blacklisted Firefox due to the crypto spoofing flaw.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I agree. I also think Phil stayed too long. They should definitely fire whoever thought all a console platform needed was Call of Duty, Elder Scrolls, and Fallout to survive. Asha and crew are still saying they need more Elder Scrolls and Fallout games. They simply don't get it.
    • Macbook Air is an appealing option, as are plethora of Windows devices with various different CPU's
    • Mozilla highlights Firefox Nova 2026 redesign and more upcoming features with new roadmap by Sayan Sen Last month Mozilla confirmed that Firefox was set to get a major redesign this year. Dubbed "Project Nova", it can already be tested and will roll out to all users later this year.The idea is to keep the browser competitive in a rapidly evolving internet landscape. As such the revamp focuses on improving privacy, usability, performance, accessibility, and customization. Key privacy features including the built-in VPN, private browsing mode, and Enhanced Tracking Protection, will be more visible and easier to manage, while users will have the option to disable AI features entirely through a dedicated kill switch. Additionally, the redesign promises faster page loading, the return of Compact mode, expanded personalization options, and stronger accessibility support. You can find the full details in the dedicated piece linked above. In a new blog post today the company once again reiterated on Nova and also emphasized other new and upcoming features like the settings revamp that is intended to make it easier for users to understand browser settings. In order to make it simpler for users to keep up with such features Mozilla today is launching Firefox roadmap. Hence enthusiasts and interested users will be able to check out what's cooking and also share feedback about the upcoming additions. Alongside the roadmap announcement, Mozilla also highlighted what's new in Firefox 152. One of the biggest additions is the arrival of Tab Groups on Android. The feature, which has already been helping desktop users organize large numbers of tabs, is now beginning to roll out on mobile. Users will be able to group related tabs together, assign names and colors to them, and return to them later. Mozilla says support for iOS will arrive later this year. Firefox 152 also introduces the aforementioned redesigned Settings experience. The company says the changes are meant to make controls easier to find and help users discover features they may not have previously known about. Existing preferences are not changing, though they are now better organized. Another notable addition is the new Blocked Tracker Widget, which provides a visual overview of Firefox's privacy protections by showing how many trackers have been blocked over time and the types of tracking activity the browser has stopped. Looking ahead, Mozilla revealed several upcoming roadmap features. They include customizable keyboard shortcuts, as well as enhanced PDF editing tools that will allow documents to be split, merged, and reorganized directly within Firefox. The company is also working on bringing Multi-Account Containers into the native Firefox experience thus removing the need for a separate extension. Meanwhile Firefox's built-in VPN is set to expand to mobile devices. Mozilla is also developing AI-powered features like Quick Answers, which can provide concise responses to voice queries, and Smart Window, its optional AI browsing experience that is now available without a waitlist. Finally, a new Power Saving Mode is in the works and will help reduce the impact of resource-heavy tabs on mobile devices in order to extend battery life. The video below summarizes the upcoming changes in an easy to understand format: You can find the announcement blog post here on Mozilla's official website.
    • Dead on arrival at that price. Like they missed the mark by multiple hundreds of dollars - this should actually undercut the Macbook Air at $899 if they want any sort of sales / further adoption of WoA
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      511
    2. 2
      +Edouard
      199
    3. 3
      PsYcHoKiLLa
      109
    4. 4
      Steven P.
      89
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!