Firefox also vulnerable to Windows cursor flaw

By
Follow google news

Researchers are warning users of Mozilla's Firefox 2.0 on Windows computers that they are vulnerable to attacks exploiting the animated cursor (.ani) bug.

Firefox also vulnerable to Windows cursor flaw
Alexander Sotirov, a researcher for the security company Determina who discovered the vulnerability, posted a demonstration online of an .ani exploit that hijacks a Windows machine using the Firefox web browser.

There is no flaw in the Firefox source code itself, but an attacker could exploit the Windows vulnerability using the application programming interface (API) feature in Firefox, Sotirov said.

Hackers are already known to be exploiting the .ani vulnerability, which was made public by Microsoft last week, but only on computers using Internet Explorer. Microsoft released an out-of-cycle patch on Tuesday to tackle the flaw.

“The reason for the confusion over Firefox is that an exploit that works against it has not become public,” said Sotirov. “So in a sense, since there are no attacks in the wild, it is safer. But people should also consider that the bad guys will figure out how to exploit Firefox.”

Sotirov advises users to refrain from using Windows API until they have installed the MS07-017 patch. Mozilla could not be immediately reached for comment.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

Log In

  |  Forgot your password?