30 Mar 2007
Microsoft is warning that attackers are actively exploiting an unpatched vulnerability in animated cursor (.ani) files for Windows.
Security vendors have seen targeted attacks that used malformed .ani files. The flaw could allow attackers to take control of a system with no user interaction.
The attack is launched when the user receives a specially crafted .ani file embedded in either a web page or email. The file is installed on the user's system and then delivers its malicious payload.
Nearly all supported versions of Windows and Internet Explorer are vulnerable to the attack. Only users running Windows Vista and Internet Explorer 7 in protected mode appear to be safe, according to Microsoft.
In protected mode, no file is allowed to access or modify any system files without user permission.
Alternative browsers such as Firefox and Opera do not appear to be vulnerable to the attack.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
My client is a well established, non profit organisation;...
PHP Web Developer – £30,000 - £35,000 PHP, MySQL, HTML...
HEAD OF DIGITAL - London - £80-95K + Excellent Bens...
Agile C# Developer - (North London) £55,000 - £65,000...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Firefox is also vulnerable
Determina also discovered that under certain circumstances Mozilla Firefox uses the same underlying Windows code for processing ANI files, and can be exploited similarly to Internet Explorer
Posted by: cas 30 Mar 2007