eWeek Security Watch
Advertisement
Advertisement
April 2, 2007 9:29 AM

Microsoft Jumps Schedule to Patch ANI



Microsoft is jumping its regular monthly patch schedule to release a patch this Tuesday for the animated cursor attack that's been roughhousing Windows users since it was discovered last week.

Update MS07-017 will take care of this vulnerability in Windows Animated Cursor Handling, a component of Windows. The regular schedule would have been for patches to come out on Tuesday, April 10. However, Microsoft said in a statement, the company "is aware of the existence of a public attack utilizing the vulnerability."

Testing has been completed earlier than anticipated, Microsoft said, and is being released so as to help protect customers.

The company said its ongoing monitoring of attack data indicates that the attacks and customer impact have been limited. Microsoft is encouraging users to download MS07-17 to protect themselves from current exploitation.

Consumers who use Automatic Updates will be updated automatically. You can also manually download the update at Windows Update. More information is available here.


TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/10701

Comments (4)

GregC :

Nice info, except that the patch isn't there and there isn't any information on Microsoft at all regarding a MS07-17 download or a patch in Windows Update for ANI Zero-day.

Are you sure you got this one right?

R Bags :

This vulnerability was not "discovered last week". Looking at an article on your own website (http://securitywatch.eweek.com/exploits_and_attacks/ani_zero_day_takes_new_turns_to_the_ubernasty.html?kc=EWNAVEMNL040207EOAD)
notes that "Microsoft was first alerted to the Windows animated cursor vulnerability on Dec. 20 by a security researcher at Determina."

So they've been sitting on it for over 3 months, and are only now getting around to it 'cause it's so nasty. In the meantime, it took M$ a mere 3 days to respond to the first DRM crack (http://www.schneier.com/essay-126.html)

Who does M$ look out for?
Itself-obviously.

Denny :

There are NO critical updates available on MS Update site right now

We have been waiting for this patch; you say it's out ? Where ?

Marjorie Miller :

I checked the history of my downloads, and do not see MS07-17, and am wondering if it is on my computer. There was a download came in yesterday while I was in here, but it had a different number. Can you tell me anything about it, or what I should look for. Thank you.

Marjorie Miller

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
eWEEK Quick LInks

Ziff Davis Enterprise