Sneaky Microsoft plug-in puts Firefox users at risk


Recommended Posts

Sneaky Microsoft plug-in puts Firefox users at risk

An add-on that Microsoft silently slipped into Mozilla's Firefox last February leaves that browser open to attack, Microsoft's security engineers acknowledged earlier this week.

One of the 13 security bulletins Microsoft released Tuesday affects not only Internet Explorer (IE), but also Firefox, thanks to a Microsoft-made plug-in pushed to Firefox users eight months ago in an update delivered via Windows Update.

"While the vulnerability is in an IE component, there is an attack vector for Firefox users as well," admitted Microsoft engineers in a post to the company's Security Research & Defense blog on Tuesday. "The reason is that .NET Framework 3.5 SP1 installs a 'Windows Presentation Foundation' plug-in in Firefox."

For the rest of the article

http://news.idg.no/cw/art.cfm?id=5CF0A4A7-...45F5A54F2136086

Consider that add-on uninstalled from my system. Idiots.

I just got the notice from Firefox today. Said the Microsoft.NET Framework Assistant and Windows Presentation Foundation would cause instability and you know what, I have noticed some hanging the last day or so with Firefox open that I never noticed before. Could be related or maybe not. Will see if the issue pops up again.

How do you remove plugins from the blocklist?

EDIT: Fixed. I had to turn off extensions.blocklist.enabled in about:config and reinstall the framework assistant. (Mozilla removed it from their repository. I found it here: http://mirror.atlanticmetro.net/mozilla/addons/9449/)

Do NOT block things on my computer without permission or a way to re-enable them, Mozilla.

Edited by GreyWolfSC
Probably.

It was also a .NET Framework 3.5 plugin getting installed on firefox anyway.

pretty much,yes

How do you remove plugins from the blocklist?

EDIT: Fixed. I had to turn off extensions.blocklist.enabled in about:config and reinstall the framework assistant. (Mozilla removed it from their repository. I found it here: http://mirror.atlanticmetro.net/mozilla/addons/9449/)

Do NOT block things on my computer without permission or a way to re-enable them, Mozilla.

your link is broken , remove the ")" from the end of the link

:)

I just got the notice from Firefox today. Said the Microsoft.NET Framework Assistant and Windows Presentation Foundation would cause instability and you know what, I have noticed some hanging the last day or so with Firefox open that I never noticed before. Could be related or maybe not. Will see if the issue pops up again.

same here, and also noticed my Firefox hanging recently. I'd prefer no Firefox secret installations from Microsoft if they are reading this ...

same here, and also noticed my Firefox hanging recently. I'd prefer no Firefox secret installations from Microsoft if they are reading this ...

It's not a secret Firefox installation. The plug-in is installed as part of the .NET Framework and Firefox picks it up automatically. If anything, we should complain to Mozilla for the browser not asking if the "found" plugin should be added. Their methodology could easily activate a hidden malware plugin the same way.

Strangely this morning when I turned my monitor on (My PC is on constantly) I had a warning from Firefox that it had disabled the Windows Foundation plugin (when checking the plugins it just says "known to cause security issues") and it directed me to the webpage https://en-gb.www.mozilla.com/en-GB/blocklist/

I just got the notice from Firefox today. Said the Microsoft.NET Framework Assistant and Windows Presentation Foundation would cause instability and you know what, I have noticed some hanging the last day or so with Firefox open that I never noticed before. Could be related or maybe not. Will see if the issue pops up again.

I got the message yesterday as well, right before firefox crashed on me. :no:

Mozilla is in your browser, disabling your addons ;)

screw that sh*t

its been all over the net how to disable/remove this Microsoft addon long before they enabled the option

i do not need Mozilla looking out for me

That's what I'm sayin'. I bet Mozilla wouldn't have liked it if Microsoft had uninstalled and blacklisted Firefox due to the crypto spoofing flaw.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • UK to ban under-16s from social media following a six-week trial with teenagers by Paul Hill Credit: Pexels A few months ago, Neowin reported that the UK was trialing a social media ban with 300 teenagers for six weeks, that testing has come to an end, and Prime Minister Keir Starmer has announced that the country will ban under-16s from social media. Starmer said that this technology is making children unhappy and making it easier for bullies to harass and abuse them. He continued to talk about the addictive nature of social media, saying that it uses an infinite scroll designed to lock users in for hours. He said this interferes with children doing their homework, reading, playing with friends outside, and going to bed on time. Tackling the idea that nothing can be done about social media, Starmer said: The government’s action won’t stop at social media either, the PM said. It plans to take action on gaming services and livestreaming platforms. Right now, he said, strangers can contact any child unchecked. He said this wouldn’t happen in real life, and the government is going to stop it from happening online, too. The Labour government has overseen the introduction of the Online Safety Act, a big change to the internet which includes age verification on adult websites. This has led to a fair bit of backlash, but overall, the government is pushing ahead with these changes.
    • Still using Hexchat every day but i would not consider it Retro 😛
    • HONOR Robot Phone unveils first Cinematic Video at Shanghai International Film Festival by Steven Parker Global AI device ecosystem company HONOR announced on June 13 that its revolutionary HONOR Robot Phone made its professional imaging debut at the 28th Shanghai International Film Festival (SIFF), demonstrating the result of its mobile videography capabilities for the first time. As the official mobile photography and videography partner of the 28th Shanghai International Film Festival, HONOR empowers this premier cinematic event with cutting-edge mobile imaging technology. Marking the global debut of the first cinematic video it captured, Robot Phone breaks down the boundaries between mobile imaging and professional filmmaking, ushering in a new paradigm for the deep integration of technology and cinematic art. In the video published on HONOR’s official channel (above), Robot Phone was used byELLEMEN to capture cinematic video portraits for the SIFF jury members. With its exceptional stability and cinema-grade imaging capabilities, the device redefines the art of portrait filmmaking, faithfully reproducing the rich tonal gradations and nuanced color transitions associated with film photography. The result is a new level of visual sophistication, creating high-end cinematic imagery that seamlessly blends atmosphere with narrative tension. The video released for the Robot Phone showcases the powerful stabilization capabilities of its built-in gimbal system, delivering exceptionally smooth handheld camera movement while preserving full image quality. By minimizing reliance on electronic image stabilization, the device effectively avoids the image cropping and quality loss typically associated with digital stabilization methods. Representing an innovative leap in form factor, the HONOR Robot Phone features the industry's smallest titanium alloy gimbal, delivering ultra-precision, extreme flexibility, and superior stability. Driven by high-performance motors, the gimbal rises dynamically, breaking free from the physical limitations of traditional camera modules. Combined with advanced AI algorithms that enable intelligent object tracking and various movements with stable shots, the device significantly simplifies video creation and reshapes both the equipment choices and creative habits of modern users. Notably, the Robot Phone will be the first product that features the results of HONOR's strategic technological partnership with ARRI, the world-renowned designer and manufacturer of professional camera technology for cinematic storytelling. From Cannes to Shanghai, the HONOR Robot Phone continues to lead the mobile imaging industry into an entirely new stage of development. Moving forward, HONOR will leverage cutting-edge AI and mobile imaging technologies to unlock new creative possibilities and extend cinematic standards for visual expression from the world of high-end filmmaking to the next generation of content creators. Learn more about the HONOR Robot Phone here: https://www.honor.com/global/events/honor-robot-phone/
    • I'll wait for the root cause analysis. Looks like it's HP, Lenova, and certain configurations that are askew, hardly "all of windows." Time will tell.
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      510
    2. 2
      +Edouard
      200
    3. 3
      PsYcHoKiLLa
      137
    4. 4
      ATLien_0
      91
    5. 5
      Steven P.
      83
  • Tell a friend

    Love Neowin? Tell a friend!