March 30, 2007
Scary Windows Vulnerability

Cool video of the latest Windows vulnerability, affecting Vista, XP, 2003 and others due to Animated cursors. The Microsoft advisory is here. The result is a crash-reload loop of explorer crashing, restarting itself, crashing, restarting itself, et infinitum.

What's really scary is that it doesn't seem to be affected by UAC or any of the new security precautions. It does still require the specially crafted ".ani" file to get onto the local system, but these days that still isn't that hard I don't think. Hey, it's just an animated cursor, right? :) This is 0-day because it's apparently been seen in the wild.... Slashdot flamefest here.

Of course, who uses animated cursors anymore. Most likely this will only hit 12 year old girls installing my little pony cursor sets.





Posted by Arcterex at March 30, 2007 03:31 PM