Most Popular Stories
- Five open source content management systems you should know about
- Hard times attract cybercrime boom
- CMS Watch says enterprise search vendors are opening up
- Netbooks eat into Microsoft's revenues
- VMware reduces storage requirements of desktop VMs by 70 percent
- Analyst: Apple will launch netbook competitor in response to slowdown
Events
Sponsored Links
Latest News
Free Newsletter
Popular Topics
Whitepapers
- Web Services Addressing 1.0 - Metadata
- Video Webinar: Using Secure Remote Management to Drive the Convergence of IT Operations and Security Compliance
- Collaboration and Social Media: Taking Stock of Today's Experiences and Tomorrow's Opportunities
- The Case for an Untethered Enterprise
- How Social Computing, Team Collaboration, and Enterprise Content Management Drive Competitive Advantage
- IM and Presence: Achieving Mission Critical Status in the Enterprise
Firefox 2/IE 7 animated cursor exploit on the way
In a column for ZDnet, George Ou reveals that security firm Determina plans to release a proof of concept animated cursor exploit that will allow attackers to hijack Mozilla 2 and IE7 running on Vista. An attack could allegedly be stopped by Microsoft's DEP (Data Execution Prevention) in Windows XP SP2 and Vista but is confoundingly turned off by default in most Windows programs. Interestingly enough, IE7 has the advantage here, as Ou writes, "What's interesting about this is the fact that Firefox doesn't have the benefit of Protected Mode under Vista, which can somewhat mitigate the damage that can be done if Internet Explorer 7 is exploited by this vulnerability." Determina is waiting for Mozilla to issue a patch before releasing the exploit code. As you will recall, Microsoft will be releasing a patch for the vulnerability today.
For more on the attack:
- see this ZDnet column
Related Stories
- Hackers exploiting unpatched Windows DNS bug
- Mozilla to issue workaround for .ANI bug
- Windows flaw gets critical, patch coming tomorrow
- Zero-day Windows bug effects Vista, XP, Windows 2K
- New version of Firefox patches FTP flaw
- Symantec: Vista vulnerable to legacy exploits
- New Microsoft Word zero-day attack on the loose
- Zero-day bugs remain after Microsoft Patch Tuesday
- IE, Firefox vulnerabilities crop up
- Patch Tuesday: Two's company
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceSarbox | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceBiotech | FierceBioResearcher | FiercePharma | FierceVaccines | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2008 FierceMarkets, Inc. All rights reserved. |
![]() |





