YNOT
  • Home
  • Industry News
    • Adult Business News
    • Adult Novelty News
    • YNOT Magazine
    • EU News
    • Opinions
    • Picture Galleries
  • PR Wire
    • Adult Company News
    • Adult Retail News
    • Adult Talent News
    • Adult Videos News
  • Podcasts
  • Industry Guides
    • Adult Affiliate Guide
    • Affiliate Marketing for Beginners
    • Top Adult Traffic Networks
    • Top Adult PR Agents
    • Funding an Adult Business
  • Business Directory
    • View Categories
    • View Listings
    • Submit Listing
  • Newsletters
  • Industry Events
    • Events Calendar
    • YNOT Cam Awards | Hollywood
    • YNOT Awards | Prague
    • YNOT Cammunity
    • YNOT Summit
    • YNOT Reunion
  • Login with YNOT ID

Microsoft to Release Patch for Cursor Vulnerability Prior to Regular Monthly Security Update

Posted On 03 Apr 2007
By : admin

REDMOND, WA — Microsoft announced over the weekend that it would make a patch available for its animated cursor flaw this week, rather than wait until the scheduled monthly security update due to take place on April 10th.In an email to CNET/News.com, a Microsoft representative stated that “Since testing has been completed earlier than anticipated, Microsoft has released the update ahead of schedule to help protect customers.”

A patch for the flaw is due to be released today.

According to the Microsoft advisory, the threat is “caused by insufficient format validation prior to rendering cursors, animated cursors, and icons.”

The advisory also states that attackers “could try to exploit the vulnerability by creating a specially crafted web page,” and/or “create a specially-crafted email message and send it to an affected system.”

“Upon viewing a web page, previewing or reading a specially crafted message, or opening a specially crafted email attachment the attacker could cause the affected system to execute code,” the advisory states. “While animated cursors typically are associated with the .ani file extension, a successful attack is not constrained by this file type.”

It is not necessary for a user to actually click anything on a website that contains the malicious code; merely visiting such a site is sufficient to trigger infection.

Microsoft originally issued its advisory concerning the flaw last Thursday, and by Friday malicious code designed to exploit the flaw in the way Windows handles animated cursor files (.ani) was circulating on the Web.

CNET/News.com also reports that, according to Arbor Networks, the malicious code exploiting the flaw appears to be originating from the following sites:

wsfgfdgrtyhgfd.net
85.255.113.4
uniq-soft.com
fdghewrtewrtyrew.biz
newasp.com.cn

As a workaround solution, Microsoft suggests that users read e-mail messages “in plain text format if you are using Outlook 2002 or a later version, or Windows Mail to help protect yourself from the HTML e-mail preview attack vector.” The company cautions, however, that reading email in plain text on Windows Vista Mail “does not mitigate attempts to exploit the vulnerability when Forwarding and Replying to mail sent by an attacker,” and reading email in plain text on Outlook Express “does not mitigate attempts to exploit this vulnerability.”

The flaw does not affect Firefox or Opera Browsers.

For more information, refer to the Microsoft advisory at: http://www.microsoft.com/technet/security/advisory/935423.mspx

  • google-share
Previous Story

Free Speech Coalition Comments on 2257 Case Ruling

Next Story

Phillippine News Site Subjected to ‘Porn Spam Attack;’ Over 27,000 Porn Trackbacks Added

Leave a Reply Cancel reply

You must be logged in to post a comment.

Sponsor

YNOT Shoot Me

YNOTShootMe.com has exclusive pics from adult industry business events. Check it out!

YNOT Directory

  • Clickadu – Your trusted traffic souce
    Marketing & Traffic Services
  • Adult Centro
    Online Content Providers
  • Sex Dolls Affiliate Program
    Other Affiliate Programs
  • Premiere Listing

    CCBill

    More Details

RECENT

POPULAR

COMMENTS

Birthday Girl Chloe Amour Named Evil Angel of the Month

Posted On 09 May 2025

Mindi Mink and Black Label Magazine Present: Taboo Temptations Episode Three

Posted On 09 May 2025
MojoHost to Roll Out Powerful New GPU Servers

MojoHost Rolling Out Powerful New GPU Servers

Posted On 09 May 2025

Vanessa, Meet Vivid

Posted On 29 Sep 2014
Laila Mickelwaite and Exodus Cry

Laila Mickelwaite, Exodus Cry and their Crusade Against Porn

Posted On 03 May 2021

Sex Toy Collective Dildo Sculptor

Posted On 19 Mar 2019

Find a good sex toy is now a problem,...

Posted On 18 Mar 2024

Thanks to the variety of sex toys, I can...

Posted On 02 Feb 2024

I understand the concerns about...

Posted On 05 Jan 2024

Sponsor

Sitemap
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.OkPrivacy Policy