MSFN Forum: Vulnerability in Windows Animated Cursor Handling - MSFN Forum

Jump to content



Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Vulnerability in Windows Animated Cursor Handling Microsoft Security Advisory (935423) Rate Topic: -----

#1 User is offline   DigeratiPrime 

  • MSFN Junkie
  • Group: Super Moderator
  • Posts: 3,490
  • Joined: 18-August 04
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 02 April 2007 - 09:41 PM

The Video :ph34r: : http://www.kissyoutu...h?v=hf0S0Vk7j6I

http://www.avertlabs...rch/blog/?p=233

Quote

Last night I had a chance to test Vista's vulnerability. In the process of setting up the environment, I dragged and dropped a malicious ANI file to the desktop. This causes Vista to enter an endless crash-restart loop. I captured a video of this occurring.


http://www.microsoft.com/technet/security/...ory/935423.mspx

Quote

Microsoft is investigating new public reports of attacks exploiting a vulnerability in the way Microsoft Windows handles animated cursor (.ani) files. In order for this attack to be carried out, a user must either visit a Web site that contains a Web page that is used to exploit the vulnerability or view a specially crafted e-mail message or email attachment sent to them by an attacker.


http://www.kb.cert.org/vuls/id/191609

Quote

Microsoft Windows animated cursor ANI header stack buffer overflow
Microsoft Windows contains a stack buffer overflow in the handling of animated cursor files. This vulnerability may allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.


http://digg.com/microsoft/Windows_Vista_Su...of_McAfee_VIDEO

Quote

Vista pwnd by Animated Cursor.

For those people who will say "turn off animated cursors" and such, I don't think that's a solution. IE allows a webpage (or email if you're using the IE rendering engine in Outlook) to replace your cursor using some IE-specific CSS code. It's as easy as changing the background for a webpage. Examples:

body {cursor: url('cursor.ani');}
<BODY style="CURSOR: url('cursor.ani')">
<BODY style="CURSOR: url('http://www.example.com/cursor.ani')">

You can do it for the <BODY> element, or for other elements like <A>s. It then loads the specified .ANI file which exploits the hole in IE.

I am almost positive there is no way to disable this in IE.


http://www.digg.com/programming/Make_IE_cr..._post_HTML_code

Quote

MSIE 6 SP 2 with all the security patches, including the August 2005 security patch, will crash when meeting malformed HTML code involving and vertical-align like this: First Paragraph Second Paragraph Everything was nicely reported and clearly explained in october 2003 and the bug is still reproducible, 100% of the time.


From what I gather only users on Vista running IE7 in protected mode with UAC on are protected, or those using Firefox/Opera :whistle:


#2 User is offline   DigeratiPrime 

  • MSFN Junkie
  • Group: Super Moderator
  • Posts: 3,490
  • Joined: 18-August 04
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 02 April 2007 - 11:32 PM

more news...

http://www.informationweek.com/software/sh...cleID=198701907

Quote

Microsoft First Notified Of .ANI Bug In December
An exploit for the zero-day vulnerability hit the wild last week, more than three months after Microsoft learned of the bug. Microsoft says it took more than three months to craft the patch.


http://www.informationweek.com/news/showAr...cleID=198701798

Quote

Attacks Escalate As Microsoft Announces Emergency .ANI Patch
Microsoft is getting ready to release an off-cycle patch Tuesday for the bug that has spawned more than 100 malicious sites and a worm over the last few days.


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2011 msfn.org
Privacy Policy