Windows animated cursor flaw--150 sites infected

Robert Vamosi | April 2, 2007 1:30 PM PDT

Summary

There's a new Microsoft Windows vulnerability being exploited across the Internet on over 150 Web sites. Here's what to do about it.

Topics

There's a new Microsoft Windows vulnerability being exploited across the Internet on over 150 Web sites. The vulnerability is caused by an unspecified error in the way Windows 2000, XP, and Vista handles animated cursors.

Animated cursors allow a mouse pointer to appear animated on a Web site. The feature is often designated by the .ani suffix, but attacks for this vulnerability are not constrained by this file type so simply blocking .ani files won't necessarily protect a PC. Successful exploitation can result in memory corruption when processing cursors, animated cursors, and icons. According to Arbor Networks, the malicious code on compromised Web sites exploiting this flaw appears to be originating from the following sites, which you may want to block:

wsfgfdgrtyhgfd.net

85.255.113.4

uniq-soft.com

fdghewrtewrtyrew.biz

newasp.com.cn

To become infected, users must be using Internet Explorer 6 or 7; there is no need to click, just visiting an infected site is enough for an infection. The flaw does not affect Firefox or Opera Internet Browsers. Microsoft will release a patch on April 3, 2007. Until a patch is released, users should browse the Internet using a non-Internet Explorer browser.

Additional Resources

Microsoft: Advisory 935423

NIST: CVE-2007-0038

Arbor Networks: Any Ani file could infect you

Internet Threat Rating 8: How we rate


Quick Facts

Name: Windows animated cursor attack

Date first reported: 03/29/07

CVE Number: CVE 2007-0038

Vulnerable software: Microsoft Windows 2000, SP1 through Windows Vista.

What it does: Causes a denial of service attack (persistent reboot) or could allow remote access.

Recommendations: Use an Internet browser other than Microsoft Internet Explorer, such as Firefox or Opera.

Exploit code available: Yes

Vendor patch available: Expected April 3, 2007.

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity