|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
Attackers exploit zero-day Windows flaw By Dawn Kawamoto, CNET News.com April 02, 2007 URL: http://www.zdnet.com.au/news/security/soa/Attackers-exploit-zero-day-Windows-flaw/0,130061744,339274628,00.htm
A zero-day exploit that takes advantage of a vulnerability in the Windows cursor could be spreading rapidly. The hole in the Windows animated cursor, which was flagged in a Microsoft advisory last week, has moved from a targeted attack to one that is widespread, said Johannes Ullrich, chief research officer for the Sans Institute, which also issued an advisory. Attackers also on Thursday launched a Trojan spam that dupes users into thinking it's an Internet Explorer 7 beta, according to a Sans advisory. The Trojan uses the same file name as Microsoft's legitimate IE 7 betas, making detection more difficult, Ullrich noted. "Antivirus software was initially pretty useless in combating it," Ullrich said. "It was spammed out quickly and probably used an existing spam network." He said, however, that users have to click on a link to have their systems affected, so it is less of a threat than the Windows animated cursor zero-day flaw, or a security hole that has been publicly disclosed but not fixed. "With the (animated cursor), you don't have to click on a link to get it to launch," Ullrich said. "You just have to open a malicious e-mail or go to a malicious Web site." Several dozen Web sites have become infected with the exploit in the past day, and Microsoft has yet to issue a patch, he added.
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |