Computer Help Community

Community

Cyber Tech Help Community

New Tutorials

PC Tutorials

New Downloads

PC Downloads

Member Testimonials

Open Member Quote   Just a quick note to say thank you for assisting me with my annoying spyware issues a few weeks ago. The response I got was EXTREMELY swift, and I have learned alot from reading your message forums! - methdodius  Close Member Quote
Member Testimonials
MY CYBER TECH HELP

LATEST TOPICS

Tech Help Community

Free Antivirus Scan

Free Virus Scan and a listing of the top 10 viruses in the wild - Free Antivirus Scan
Free Online Antivirus Scan

File Extension Database

Find what program a filetype belongs to in our searchable File Extension Database.
File Extension Database

Services

See what services Cyber Tech Help can offer your business or website: CTH Services
CTH Services

Related MS Links

Related Links
Cyber Tech Help Community

To the top of the page to top

 



3rd Party Patches Critical Windows Flaw

Latest News Latest News | News ArchiveNews Archive | Cyber Tech Help News RSS Feed!

3rd Party Patches Critical Windows Flaw3rd Party Patches Critical Windows Flaw

Posted by: Tweaker
Date added: 13:15, 31st March 2007 GMT
Source: Beta News

Microsoft Windows

Not content to wait for Microsoft to remedy the issue, independent security firm eEye released a temporary patch for a critical flaw affecting Windows that can lead to a crash-restart-crash loop. But Microsoft does not recommend such third-party patches.

The potential exploit is trigger by a buffer overflow in an animated cursor file. A similar flaw was discovered in early 2005, but did not apparently affect Windows XP Service Pack 2. The new issue, discovered by McAfee's Avert labs does seem to impact XP SP2 and Windows Vista, as well as Windows 2000 SP4 and versions of Windows Server 2003 from the initial release through to SP1.

Avert Labs' video of the incident, posted to YouTube, shows a Vista system wherein the test file apparently trying to load the custom animated cursor. When the operating system detects a crash, it first tries to save vital data prior to a restart sequence - one of Vista's newer features. It then informs the user that Windows Explorer has crashed.

eEye says its temporary patch prevents the flaw from being exploited, but does not correct the underlying problem.

"Almost a year ago to the day, we released one of the first third-party patches, proactively providing Windows users temporary protection against a serious zero-day vulnerability; we are doing it yet again," said eEye co-founder Marc Maiffret. "Unlike last year's JScript Vulnerability, there are no immediately effective means of mitigation for this zero-day vulnerability. As a result, we encourage all Windows users to take advantage of our free patch until other means of protection become available."

Microsoft, for its part, said Thursday it has activated its Software Security Incident Response Process, and issued a security advisory on the matter. One method of attack can occur by embedding an malicious animated cursor into an e-mail, the company said.

"The most potent attack method used by this vulnerability is conducted by embedding a malicious .ANI file within an HTML web page. Doing so allows the vulnerability to be exploited with minimal user interaction by simply coaxing a user to follow a hyperlink and visit a malicious web site," reported eEye. "Other exploit vectors exist including Microsoft Office applications since they also rely on the same .ANI processing code, making email delivery also a potent threat by using Microsoft Office attachments."

In a later update, Microsoft acknowledged that Outlook Express users are vulnerable, even if they disable HTML e-mail. Outlook 2007 users are protected, as are Windows Mail users on Vista - as long as they do not reply or forward the malicious e-mail.

eEye's zero-day patch is available for download from the security firm's Web site. Microsoft has not yet said when it will issue a fix, although the next "Patch Tuesday" is slated for April 10. The company could choose to release an out-of-cycle update if warranted by the severity of the problem.

Tools:  Tools: Post a comment | Link to this news item | Send to a friend | Submit News

 

Post a commentPost a comment

Error: You are not logged in.

In order to leave comments to news articles you must be a Cyber Tech Help Member.

Registration is completely free!  Register to become a member!  Register to become a member

Along with access to leave comments to news articles you will be able to ask any computing questions you might have on the Cyber Tech Help Forums.

 

[ To the top of the page To top | Latest News Latest News | News Archive News Archive | Cyber Tech Help News RSS Feed! ]