On mySimon: Logitech MX Revolution Laser Mouse
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Apr 4, 2007 10:25:00 PM

Mozilla is looking at delivering its own remedy for a Windows flaw that could let attackers commandeer a PC running the Microsoft operating system software.

Microsoft broke with its monthly patch cycle Tuesday to fix the bug, which cybercrooks had been using since last week to attack Windows PCs. The flaw relates to the way Windows handles animated cursors and could let an attacker commandeer a PC when the user views a malicious Web site or e-mail message.

The vulnerability could be exploited through any Windows application that relies on the operating system to handle animated cursor files. This includes Mozilla's Firefox Web browser, which according to some security experts exposes Windows Vista users to greater risk than Internet Explorer 7 because the latest Microsoft browser has additional security features.

"The vulnerability is caused by a Windows error…it can be exploited through both Firefox and Internet Explorer," Mike Schroepfer, vice president of engineering at Mozilla, said in a statement. "We are investigating issuing a workaround within Firefox in an upcoming security release." Mozilla coordinates Firefox development.

The Firefox workaround could be welcome for those users who, for whatever reason, don't install Microsoft's fix. Some compatibility problems with the Microsoft update have been reported. "Microsoft has issued a patch to fix Windows and we encourage all Windows users to apply this update immediately," Schroepfer said.

Security experts at Determina, which reported the animated cursor flaw to Microsoft, have published a video that shows how a Vista PC can be compromised by exploiting the flaw and how Firefox users are at a higher risk than IE 7 users.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 10 Talkback(s)
agreed
dont use microsoft apis except where you have to

theyre poison

kthx

archy (Read the rest)
Posted by: Resuna Posted on: 04/10/07 You are currently: a Guest | | Terms of Use
The patch doesn't work for me  galileon | 04/05/07
Firefox users are at a higher risk than IE 7 users.  qmlscycrajg | 04/05/07
how d'ya figure  galileon | 04/05/07
Firefox extensions go Evil - Critical Vulnerabilities  qmlscycrajg | 04/05/07
Fixed the day after  gotitright | 04/09/07
Firefox, stick with keeping your browser on point  Boot_Agnostic | 04/05/07
agreed  Resuna | 04/10/07
MS Updates are just a pain  Uralbas | 04/06/07
Google and run gpedit.msc  Boot_Agnostic | 04/06/07
dont support windows proprietary formats  Resuna | 04/10/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More