• On MovieTome: TRANSFORMERS 2 SPOILERS!

April 4, 2007 3:25 PM PDT

Mozilla mulls Windows cursor flaw fix of its own

Mozilla is looking at delivering its own remedy for a Windows flaw that could let attackers commandeer a PC running the Microsoft operating system software.

Microsoft broke with its monthly patch cycle Tuesday to fix the bug, which cybercrooks had been using since last week to attack Windows PCs. The flaw relates to the way Windows handles animated cursors and could let an attacker commandeer a PC when the user views a malicious Web site or e-mail message.

The vulnerability could be exploited through any Windows application that relies on the operating system to handle animated cursor files. This includes Mozilla's Firefox Web browser, which according to some security experts exposes Windows Vista users to greater risk than Internet Explorer 7 because the latest Microsoft browser has additional security features.

"The vulnerability is caused by a Windows error?it can be exploited through both Firefox and Internet Explorer," Mike Schroepfer, vice president of engineering at Mozilla, said in a statement. "We are investigating issuing a workaround within Firefox in an upcoming security release." Mozilla coordinates Firefox development.

The Firefox workaround could be welcome for those users who, for whatever reason, don't install Microsoft's fix. Some compatibility problems with the Microsoft update have been reported. "Microsoft has issued a patch to fix Windows and we encourage all Windows users to apply this update immediately," Schroepfer said.

Security experts at Determina, which reported the animated cursor flaw to Microsoft, have published a video that shows how a Vista PC can be compromised by exploiting the flaw and how Firefox users are at a higher risk than IE 7 users.

See more CNET content tagged:
Mozilla Corp., Firefox, Microsoft Internet Explorer 7, flaw, Microsoft Internet Explorer

Add a Comment (Log in or register) 7 comments
work around for Firefox users..
by FutureGuy April 4, 2007 4:59 PM PDT
..use IE 7 for the time being.
Reply to this comment View all 3 replies
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right