Microsoft Patches Cursor Vulnerability
Just a quick post about a story that we covered in this weeks show. The story that we covered was in relation to the vulnerability in the way in which windows handles .ani files. This from Microsoft’s site issued on the 31st of March:
“Microsoft is investigating new public reports of attacks exploiting a vulnerability in the way Microsoft Windows handles animated cursor (.ani) files. In order for this attack to be carried out, a user must either visit a Web site that contains a Web page that is used to exploit the vulnerability or view a specially crafted e-mail message or email attachment sent to them by an attacker.”
Microsoft have known about this vulnerability since December 2006. The plan was to patch this vulnerability on April 10th, but due to the increasing number of attacks and the risk to users they plan to patch this on Tuesday.
Knightwise would call this slack patching, or patching a problem only when it becomes a public issue or could cause a serious loss of face for Microsoft. I too do not believe that we should have waited three and a half months for this to have happened. However, I use Firefox and I am therefore somewhat protected but I would be cautious in saying I was immune. I do after all have a Windows system. Still another argument to use an alternative other then IE.
Source: Cnet News



April 4th, 2007 at 6:32 am
Waiting for 3 months to patch something is never a good thing. It’s funny because for the first 2-4 Patch Tuesdays to blow by, nothing was released by Microsoft yet they could of released this patch. Hopefully they don’t turn this into a regular practice.
April 4th, 2007 at 7:53 am
If I knew something was not working and left it go for 3 months im sure I wouldn’t have a job anymore. I wish I was microsoft!
April 4th, 2007 at 10:19 pm
they where to busy shifting other crap into Vista, who cares if it does not work, as long as its sells !
April 4th, 2007 at 10:51 pm
I like the new Windows logo/icon. Now, how do I change the emblem on my Windows boot up screen to that one?
April 5th, 2007 at 12:13 am
If you really want it I could arrange it. The image was created by Tim King for this post.
Anyone else?
April 5th, 2007 at 8:39 am
animated cursors?? sounds like just deserts!!
April 5th, 2007 at 9:26 am
Yeah lets get that new logo set up….
April 5th, 2007 at 1:55 pm
I thought I was the resident Windows-Crank
Looks to me like I have followers. ( I always knew Brie had excellent taste !)
April 6th, 2007 at 3:53 pm
Can I have the little logo at 1280*1024 with the ggp logo in the bottom ? Would make a kick ass wallpaper.