Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Security

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

Crackin' the Kraken bot. Listen now!

Network World's Newsmaker of the Week

Wireless dangers at airports. Listen now!

Network World Panorama

Additional Resources

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

HP Live Webcast: Create a more efficient NOC HP

HP's Network Lifestyle Management can help you automate network processes and improve NOC efficiency. This webinar is part three of a four part series on Business Services Management (BSM) evolution to help you better align IT with business objectives. Register for this event scheduled for Wednesday, January 30, 2008 at 11:00 a.m. PDT/2:00 p.m. EDT to learn more. Register for this live webcast now.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

So the line of defence remains is "PIN NUMBER" Wowww what a strong security ? HSBC , invest some money...- Anonymous

Join the Discussion

Microsoft issues patch for cursor flaw

Dr. Internet By Steve Blass , Network World , 04/05/2007
Steve Blass
  • Social Web 
  • Email 
  • Feedback 
  • Close

Are there any workarounds to stop the most recent Windows animated-cursor exploit? Do you know when Microsoft will release a patch to repair the problem?

Microsoft released a patch last week to fix the animated-cursor vulnerability. This problem with the way animated cursors are handled in Internet Explorer on Windows requires only that one visit a malicious Web page designed to exploit the problem. No clicking is needed. This makes exploitation through HTML e-mail spam particularly easy and troublesome. Microsoft's advisory for this vulnerability, No. 935423, recommends setting Outlook and/or Outlook Express to display e-mail as plain-text only. Other workaround recommendations include using an alternate Web browser such as Firefox. Internet Explorer 7 on Microsoft Vista is reported to be unaffected by this vulnerability. Vista runs the browser in a protected mode unavailable in XP and earlier versions that keeps things like this animated-cursor exploit isolated from the core of the operating system. Large numbers of reported attacks based on this vulnerability are tied back to a small number of domains, and those who find themselves compromised are asked to report the incidents to the FBI through the Internet Crime Complaint Center, www.ic3.gov. This vulnerability is one you should take care of as soon as possible. Check Microsoft.com for the latest information on patch availability and keep a close eye on your systems-security monitoring tools.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code