Thursday November 20, 2008 7:15 PM AEST
Latest Comments
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM
 
"I actually love the RoboForm software myself. I use it all of the time and it takes all of the ..."
by Omarra Byrd | Nov 18, 2008 8:19 AM

Microsoft to release ANI patch a week early

  • Email a Friend
  • Print Page
Microsoft to release ANI patch a week early
By Ericka Chickowski
Apr 3, 2007 10:13 AM
Tags: Microsoft | to | release | ANI | patch | a | week | early
The ANI bug leaves open to attack any webpage email or content that can load an animated cursor, allowing attackers to run arbitrary code on users’ systems. Over the weekend ANI exploits snowballed, wrecking the weekend for many security professionals responding to attacks.

On Friday, Secunia reported the vulnerability as “extremely critical” and eEye Digital released a third-party patch to service those anxious to protect systems before Microsoft releases its sanctioned fix.

According to Ken Dunham of iDefense Labs, researchers have found over 150 malware samples utilising the vulnerability in the wild as of early Sunday morning.

He reported that a worm, a spam run and generation kits exploiting the flaw now exist in the wild. On Saturday Websense reported over 100 ANI exploitation sites in the wild.

“This is undoubtedly a serious issue that will persist for many months if not years, attacking vulnerable computers,” Dunham says.

“iDefense believes the new ANI exploit will be a long term persistent threat, one of the most significant we've seen in the past three years.”

Dunham reported that many of the ANI attack kits were based in China, with a focus on the theft of role-playing game credentials to sell on the black market. While most exploits currently impact only Windows XP SP2, he noted that the damage will likely spread.

“It's trivial to modify the exploit to work on other builds of operating systems,” he said, “iDefense has also found that it's trivial to modify the exploit to work through a Windows Explorer vector.”

Microsoft plans to release the patch this Tuesday, a full week before its regularly-scheduled patch release, in response to widespread exploits.

“Microsoft originally planned to release the update on Tuesday, April 10, 2007 as part of its regular monthly release of security bulletins,” a Microsoft spokesperson said.
“However, Microsoft is aware of the existence of a public attack utilising the vulnerability. Since testing has been completed earlier than anticipated, Microsoft has released the update ahead of schedule to help protect customers.”

The patch may not come quickly enough for bleary-eyed security professionals who have been working overtime to mitigate risks.“Happy April Fool's Day, no joking,” said Ken Dunham of iDefense Labs in an advisory on Sunday, “it will be very busy today and as we head into the work week.”

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Patch Management Whitepapers