AKB Forums

Go Back   AKB Forums > Technical sections > Operating Systems
Home Register Blogs FAQ Members List Calendar Downloads Arcade Mark Forums Read

Operating Systems Unix, DOS, Windows 9x/NT/2000/XP/2003

Troubles when posting message? Click here! :: Проблемы с отправлением сообщения? Нажмите сюда!

Reply
 
LinkBack Thread Tools Display Modes
Old Mar 30, 2007, 13:54   #1
Say no to alco like Gates
 
Hrach_Techie's Avatar
 
Join Date: Aug 2004
Location: Apparently the anti-alcoholism campaign hasn't worked very well for Gates after the last Zaher party ...
Posts: 16,259
Rep Power: 7
Reputation: 337
Microsoft Investigating Windows Zero-Day Bug

Microsoft is working on a patch for the bug that uses Internet Explorer as its main attack vector, and affects all the recent Windows releases, including Vista.

Microsoft Corp. has confirmed a new Windows zero-day bug that is already being targeted by attackers.

The vulnerability lies in the way Windows handles malformed animated cursor files and could enable a hacker to remotely take control of an infected system. The bug affects all the recent Windows releases, including its highly-touted Vista operating system. Internet Explorer is the main attack vector for the exploits.

Microsoft said in its advisory that researchers are working on a patch for the bug.

"In order for this attack to be carried out, a user must either visit a Web site that contains a Web page that is used to exploit the vulnerability, view a specially crafted e-mail message, or opening a specially crafted e-mail attachment sent to them by an attacker," Adrian Stone, a Microsoft researcher said in a blog. "While the attack appears to be targeted and not widespread, we are monitoring the issue and will update the Advisory and blog as new information becomes available."

Maarten Van Horenbeeck, a handler with the Internet Storm Center, reported on their site that they have spotted domains hosting malicious code that would exploit this vulnerability. And Craig Schmugar, a researcher at McAfee, said on his blog that McAfee analysts are seeing malicious exploit samples, as well.

"Preliminary tests demonstrate that Internet Explorer 6 and 7 running on a fully patched Windows XP SP2 are vulnerable to this attack," Schmugar wrote, adding that known exploits download and execute arbitrary .exe files. "Exploitation happens completely silently."

TrendMicro posted an advisory warning that a Trojan, named Anicmoo.ax, which is exploiting this bug, may get into a system in the form of a specially-crafted animated cursor (.ANI) file downloaded from the Internet by unsuspecting users. It may also arrive as a file embedded in HTML e-mail messages.

Microsoft said in its advisory that it has added detection to the Windows Live OneCare safety scanner for up-to-date removal of malicious software that attempts to exploit this vulnerability.

http://www.theemiratesnetwork.com/ex...4-0030488344e4
__________________
Мадмазель, Медам, Месье! "Глория" меняет курс и направляется в Кейптаун! Кому это не нравится будет расстрелян на месте. (с)

http://texneg.livejournal.com
Hrach_Techie is offline   Reply With Quote Quote selected
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Download Free Ebooks (Computers, Physics, Math and more) acid TWARM 217 Jul 3, 2008 05:12
Microsoft выпустила Service Pack2 для Windows Server 2003 {arsen} News 0 Mar 15, 2007 11:15
чят б/п Sauron Uncensored 53801 Aug 19, 2005 09:12
Windows LongHorn - New Generation of M$ Fiddlesticks!!! Hrach_Techie TWARM 0 Sep 13, 2004 14:36
Browser (User Agent) Usage Statistics acid Web Development 4 Jan 12, 2004 08:26


All times are GMT. The time now is 16:35.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
This board was founded on September 29, 2001
Powered by Viper Internet

Affordable Web Hosting | ParevNet

Buy text link