Security:
News ToolsReg ShopsTop Stories |
MS releases emergency cursor bug fixDouble-plus critical update triggers glitchesPublished Wednesday 4th April 2007 11:25 GMT Microsoft has released an out-of-sequence patch designed to address a Windows vulnerability involving the handling of cursor animation files, as well as a number of other flaws. The prime focus of the update is a stack buffer overflow flaw involving Windows' handling of animated cursor (.ANI) files. The flaw, first reported last week, creates a means for hackers to inject hostile code into unpatched systems and has become the target of widespread hacking attacks. Internet Explorer can process ANI files in HTML documents, so web pages and HTML email messages can also be vectors for the vulnerability. Microsoft responded to reports of widespread abuse of the flaw by pushing out an emergency fix on Tuesday, 3 April, a week before its regular Patch Tuesday update. The patch also addresses a number of vulnerabilities, involving privilege escalation, denial of service and remote code execution flaw. Early reports suggest a number of glitches with the update. In particular, the patch can conflict with systems running Realtek Audio cards, prompting Microsoft to release a hotfix. ® 2 comments posted — Comment period finished ErrorPosted: 15:43 4th April 2007 MS Patch Breaks Realtek AudioPosted: 16:15 4th April 2007
Track this type of story as a custom Atom/RSS feed or by email.
|
|
Top 20 stories • All The Week’s Headlines • Archive • Search