Most Popular Stories
- One on One with Arpan Shah of Microsoft Sharepoint
- IBM will snag half of India's outsoucing work by 2010
- Vendors prepare for Obama's electronic medical records change
- Teen sends 14,528 text messages in a single month
- Coke uses RFID for drink dispensers
- Forrester report predicts web content management will grow in spite of economy
Events
Sponsored Links
Free Newsletter
Latest News
Popular Topics
Whitepapers
- From Email Bankruptcy to Business Productivity
- Service Oriented Architecture
- Gartner DCMA Report
- Consumption-Based Fundamental Asset Allocation Redefines Investing -- Relevant Investing in a Post-Collapse Era
- White paper: Managing your company's wireless expense is not enough. Be BudgetCorrectâ„¢
- What Every CXO Should Know About the "Web 2.0"
Firefox 2/IE 7 animated cursor exploit on the way
In a column for ZDnet, George Ou reveals that security firm Determina plans to release a proof of concept animated cursor exploit that will allow attackers to hijack Mozilla 2 and IE7 running on Vista. An attack could allegedly be stopped by Microsoft's DEP (Data Execution Prevention) in Windows XP SP2 and Vista but is confoundingly turned off by default in most Windows programs. Interestingly enough, IE7 has the advantage here, as Ou writes, "What's interesting about this is the fact that Firefox doesn't have the benefit of Protected Mode under Vista, which can somewhat mitigate the damage that can be done if Internet Explorer 7 is exploited by this vulnerability." Determina is waiting for Mozilla to issue a patch before releasing the exploit code. As you will recall, Microsoft will be releasing a patch for the vulnerability today.
For more on the attack:
- see this ZDnet column
Related Stories
- New version of Firefox patches FTP flaw
- Zero-day Windows bug effects Vista, XP, Windows 2K
- Windows flaw gets critical, patch coming tomorrow
- Microsoft addresses many bugs in this month's Patch Tuesday
- Hackers exploiting unpatched Windows DNS bug
- Mozilla to issue workaround for .ANI bug
- Symantec: Vista vulnerable to legacy exploits
- New Microsoft Word zero-day attack on the loose
- Zero-day bugs remain after Microsoft Patch Tuesday
- IE, Firefox vulnerabilities crop up
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2009 FierceMarkets, Inc. All rights reserved. |
![]() |







Click here to get the FierceCIO:TechWatch email newsletter for FREE!
Be the first to comment