Most Popular Stories
Events
- CTO Telecom Summit – May 31-Jun 3, 2009
May 31 – June 3, 2009 — Scottsdale, AZ – Four Seasons
Sponsored Links
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Legal Applications of A2iA DocumentReaderâ„¢: Automated intelligent document classification, data extraction and search tools
- Fifteen Questions for Every ERP Software Supplier
- Managing the Mobile Enterprise Culture Shift: White Paper Download from ProfitLine
- IM and Presence: Achieving Mission Critical Status in the Enterprise
- 5 Best Practices for Smartphone Support
- The ECM Paradox: Extending Local Flexibility to Strengthen Central Control
Firefox 2/IE 7 animated cursor exploit on the way
In a column for ZDnet, George Ou reveals that security firm Determina plans to release a proof of concept animated cursor exploit that will allow attackers to hijack Mozilla 2 and IE7 running on Vista. An attack could allegedly be stopped by Microsoft’s DEP (Data Execution Prevention) in Windows XP SP2 and Vista but is confoundingly turned off by default in most Windows programs. Interestingly enough, IE7 has the advantage here, as Ou writes, “What’s interesting about this is the fact that Firefox doesn’t have the benefit of Protected Mode under Vista, which can somewhat mitigate the damage that can be done if Internet Explorer 7 is exploited by this vulnerability.” Determina is waiting for Mozilla to issue a patch before releasing the exploit code. As you will recall, Microsoft will be releasing a patch for the vulnerability today.
For more on the attack:
– see this ZDnet column
Related Stories
- Patch Tuesday: Two’s company
- IE, Firefox vulnerabilities crop up
- Zero-day bugs remain after Microsoft Patch Tuesday
- New Microsoft Word zero-day attack on the loose
- Symantec: Vista vulnerable to legacy exploits
- New version of Firefox patches FTP flaw
- Zero-day Windows bug effects Vista, XP, Windows 2K
- Windows flaw gets critical, patch coming tomorrow
- Hackers exploiting unpatched Windows DNS bug
- Mozilla to issue workaround for .ANI bug