Most Popular Stories
- Q&A: Disaster recovery when your business sits on the San Andreas Fault
- Content Marketing could be supplanting the traditional corporate blog
- Enterprise architecture at Chubb Insurance
- CFO has a role to play in ERP rollouts
- Content is the new gold
- Help desks get help at Peugeot, De Beers and University of Georgia
- A 'mobile help desk' in every pocket, from Salesforce.com
- Apple co-founder Wozniak sings Android's praises
- Four ways to better manage IT sales calls
- Section 508 web accessibility rule to change
- Survey finds many users blow by SharePoint security
- How hackers can eavesdrop on prevalent videoconferencing systems
Events
- The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - CIO Summit
March 18- 21 — Miami, FL
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- The Shortcut Guide to Secure, Managed File Transfer
- Efficiency On Demand
- Security Intelligence: Enabling Security Monitoring for Landscapes
- Storage Consolidation: Best of Both Worlds
- Enterprise Digital Assistant Leverage in the Emerging Mobile Enterprise
Microsoft plug-in for Firefox patched
Hidden in the record-breaking batch of security bulletins released by Microsoft earlier this week was one that addressed a vulnerability not in Microsoft's own product, but that of the rival Firefox browser from Mozilla. To put it bluntly, the critical bug that opened Firefox users to a critical risk is the result of Microsoft quietly pushing out an update via Windows Update eight months back.
The affected component would be the "Windows Presentation Foundation plug-in in Firefox" which typically comes via the .NET Framework 3.5 SP1. The problem is that this plug-in can be installed without the user's approval, according to Susan Bradley, a contributor to the Windows Secrets newsletter.
The danger is real, and Firefox users with the vulnerable plug-in only need to visit a rigged site to get compromised.
In addition, reports indicate that the original version of the plug-in was next to impossible to remove. This is because the "Uninstall" and "Disable" buttons for this particular plug-in are disabled by default, and removing them is complicated. The inability to easily uninstall it was later rectified in a May update.
While the latest update should resolve the issue, I would personally advocate removing the plug-in from computers you own or manage. Do a quick check of your Firefox; do you have this plug-in installed?
For more on this story:
- check out this article at Computerworld
Related Articles:
Is it only a myth that Firefox is more secure?
Mozilla plugs 13 holes in Firefox
Mega Patch Tuesday coming next week
Related Stories
- Mozilla adds vulnerable Microsoft plug-in to block list
- ALSO NOTED: First look: Vista SP1; Mozilla patches Firefox vulnerability;
- Google, Mozilla, Microsoft blacklist DigiNotar, but Apple remains silent
- Microsoft readying big Patch Tuesday next week
- Web authentication company fingers Iran for sophisticated hack
- IE9 is not a modern browser, says Mozilla
- Microsoft proposes public health approach to curb botnets
- New Windows kernel bug surfaces days before Microsoft's largest Patch Tuesday
- Microsoft to issue record number of security bulletins next Tuesday
- Mozilla ups security bug bounty to $3,000
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




