Microsoft readies emergency ANI patch——微软公司将发布动画光标补丁[翻译][原创]
发表于: 2007-4-3 08:34 5499

Microsoft readies emergency ANI patch——微软公司将发布动画光标补丁[翻译][原创]

2007-4-3 08:34
Microsoft readies emergency ANI patch
Published: 2007-04-02

Microsoft shifted gears over the weekend, announcing plans on Sunday to release an emergency patch for a vulnerability that the company has known about for more than three months.
The flaw, which occurs in the way that Windows handles animated cursor (.ANI) files, came to light last week, after attackers started using the vulnerability to compromise victims through Web and e-mail attacks. Security firm Determina had notified Microsoft of the vulnerability in December 2006, and the software giant planned to fix the issue in its regularly scheduled April patch, the company said.
Now, Microsoft will release the patch a week early.
"From our ongoing monitoring of the situation, we can say that over this weekend attacks against this vulnerability have increased somewhat--additionally, we are aware of public disclosure of proof-of-concept code," Christopher Budd, security program manager for Microsoft Security Response Center, said in a statement posted to the group's blog. "In light of these points, and based on customer feedback, we have been working around the clock to test this update and are currently planning to release the security update that addresses this issue on Tuesday April 3, 2007."
微软安全部门管理者Christopher Budd在他的Blog说道:“我们目前正在密切关注着局势,我们认为到本周周末,黑客通过这个漏洞攻击将会稍微增多,我们已经捕获到了相关的代码。我们将侧重用户的反馈意见,我们正日夜不停的测试补丁,准备在2007年4月3日发布漏洞补丁供大家下载。”
Reports of attacks and public exploits using the flaw in the way Windows handles animated-cursor (.ANI) files increased toward the end of last week. A group that uses compromised Web sites to redirect visitors to a number of Chinese sites hosting malicious content has begun to exploit the flaw to compromise victims' systems. Security Web site milw0rm.com is currently hosting two different exploits for the vulnerability. Both Immunity and the Metasploit Project have incorporated exploits for the issue into their security-checking software.
The flaw affects all versions of Windows, including Windows Vista, and can be exploited through Internet Explorer 6 and 7 as well as e-mail. Microsoft stated that the company will continue testing the patch up until release and an issue could be found that delays the release of the update.


免费 0
最新回复 (0)
登录 | 注册 方可回帖