Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

MICROSOFT

Windows Vista Suicide, Courtesy of McAfee

- Animated cursors kill Vista

By: Marius Oiaga, Technology News Editor

Windows Vista, Microsoft's extensively applauded most secure Windows platform to date can be taken down by nothing more than a mere animated cursor. I have seen this piece of news spreading,
following a security advisory posted by the Microsoft Security Response Center. But what is the real deal behind this information?

Microsoft has warned that it is aware of limited and targeted attacks impacting a critical vulnerability in Microsoft Windows Animated cursor handling. At the basis of the zero-day vulnerability is insufficient format validation, before cursors, animated cursors, and icon rendering. Security company Symantec informed that in the eventuality of a successful exploit, the attacker will be able to perform remote arbitrary code execution on the victim's machine. There are two vectors for this kind of attack, one is the Internet browser and the other is the desktop email client.

"In order for this attack to be carried out, a user must either visit a Web site that contains a Web page that is used to exploit the vulnerability or view a specially crafted e-mail message or email attachment sent to them by an attacker," according to Microsoft Security Advisory (935423).

The zero-day Windows Animated Cursor Handling vulnerability affects a set of Windows editions including Windows Vista. Because it allows for remote code execution, the .ani files vulnerability will automatically receive the highest severity rating from Microsoft, namely Critical. The Redmond Company will not downgrade the severity level of this vulnerability for Windows Vista, although the operating system has a few mitigations in place that do not expose users as much as other editions of Windows.

"Customers who are using Internet Explorer 7 on Windows Vista are protected from currently known web based attacks due to Internet Explorer 7.0 protected mode. If you are reading Outlook 2007 you are protected regardless of if you are reading the mail as plain text or not. If you are reading email using Windows Mail on Vista you are protected as long are not forwarding or replying to the attackers email," Microsoft informed.

However, despite these mitigations, Windows Vista is very much vulnerable to attacks. In the video embedded at the bottom, you will be able to see Craig Schmugar, virus research manager with McAfee, send Windows Vista into a perpetual "crash-restart" loop by simply dragging a malformed .ani file to the operating system's desktop.



MORE RELATED ARTICLES: Windows Vista Will Make the Threat Environment Evolve and Adapt Let the OS without Sin Cast the First Stone at Windows Vista Windows Vulnerabilities, Just as Severe in Vista All Windows Are Created Equal Mac OS X and Linux; No Match for Windows Windows Vista More Secure Than Mac OS X Windows Vista Into the Slaughter House Trust in Your Windows Vista SDL Beat It Mac, Windows Vista Is Better! Windows Vista – to Do or Not to Do, Security?
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


30th March 2007, 10:37 GMT | Copyright (c) 2007 Softpedia | Contact:
Read by 85,210 user(s) | Rating: | 24 vote(s) so far | Cast your vote:
Windows Vista Suicide, Courtesy of McAfee - USER OPINIONS

Comment #1 by sfraider24 on 2007-03-30, 20:46 GMT reply to this comment 
Ouch! There's your reason to wait for Windows Vista SP1...

-SF
http://www.wasatchsoftware.com/microsoft/business/windows-vista.htm

Reply #1.1 by kerouac906 on 2007-03-31, 02:43 GMT
Why? To protect us from all those pesky 'malformed' .ini files that get dragged onto our desktop? Happens every friggin day i tells ya.

This hardly qualifies as a security issue. If it happened, anyway, just restart in safe mode, delete the .ini, and find and delete the virus if that's what did it.

Comment #2 by kerouac906 on 2007-03-31, 02:45 GMT reply to this comment 
.ini => .ani in above post


go to top


SHARE YOUR OPINION ABOUT Windows Vista Suicide, Courtesy of McAfee

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive