• On BNET: 3 worst things about the iPhone 3G S
April 10, 2007 10:22 AM PDT

Windows animated cursor attack

by Robert Vamosi
There's a new Microsoft Windows vulnerability being exploited across the Internet on over 100 Web sites, according to security vendor Websense. The vulnerability is caused by an unspecified error in the way Windows 2000, XP, and Vista handles animated cursors. Animated cursors allow a mouse pointer to appear animated on a Web site. The feature is often designated by the .ani suffix, but attacks for this vulnerability are not constrained by this file type so simply blocking .ani files won't necessarily protect a PC. Users need not do anything but visit a compromised site to become infected. Antivirus vendor F-Secure reports there's also a worm associated with this vulnerability.

Successful exploitation can result in memory corruption when processing cursors, animated cursors, and icons. According to Arbor Networks, the malicious code on compromised Web sites exploiting this flaw appears to be originating from the following sites, which you may want to block:

wsfgfdgrtyhgfd.net

85.255.113.4

uniq-soft.com

fdghewrtewrtyrew.biz

newasp.com.cn

To become infected, users must be using Internet Explorer 6 or 7; there is no need to click, just visiting an infected site is enough for an infection. The flaw does not affect Firefox or Opera Internet Browsers. Microsoft released a patch within its security bulletin MS07-017.

Additional Resources

Microsoft: MS07-017

Zeroday Emergency Response Team (ZERT): Unofficial patch

NIST: CVE-2007-0038

Arbor Networks: Any Ani file could infect you

Websense: Alert

F-Secure: Blog post

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from Zero Days
Microsoft fixes nineteen flaws in seven patches; all are considered critical updates
Storm Worm strikes again
Windows dynamic DNS update mechanism
Windows Web Proxy Autodiscovery flaw
Windows animated cursor attack
Update for Internet Explorer 7
Integer overflow in Microsoft Internet Explorer 6
Internet Explorer "FolderItem" Object Access Remote Denial of Service Vulnerability
advertisement

About Zero Days

Zero Days are security threats released before or concurrent with the public disclosure of software vulnerabilities. Our new blog will keep you ahead of the criminal hackers by informing you what you are up against.

Add this feed to your online news reader

Zero Days topics