[ insider_reports_insider ] Microsoft Plans To Fix ANI Flaw Early
David Utter Staff Writer
2007-04-02
Insider Reports RSS Feed
An escalation of attacks against Internet Explorer through a vulnerability in the handling of animated cursor files will receive a patch ahead of Microsoft's customary patch date.
 | | Microsoft Plans To Fix ANI Flaw Early |  |
The malicious ANI exploit we cited last week will receive a needed patch on April 3rd, a week ahead of Patch Tuesday, the informal name for Microsoft's usual day to issue patches. It probably should have been fixed sooner.
Christopher Budd reported the advanced release date on the Microsoft Security Response blog. He noted the company has known about this little drive-by problem for some time:
I'm sure one question in people's minds is how we're able to release an update for this issue so quickly. I mentioned on Friday that this issue was first brought to us in late December 2006 and we've been working on our investigation and a security update since then.
This update was previously scheduled for release as part of the April monthly release on April 10, 2007. Due to the increased risk to customers from these latest attacks, we were able to expedite our testing to ensure an update is ready for broad distribution sooner than April 10.
Microsoft's expedited release comes as more attacks have been sighted in the wild taking advantage of the exploit. Security firm F-Secure reported a half-dozen incidents in China where a worm uses the ANI exploit to spread.
Security pros may arch their eyebrows at Microsoft's quicker response for a couple of reasons. First, they've known about the problem for a few months. Second, they completely skipped the March patch release, something which had not happened for a couple of years.
It might have been a good idea for Microsoft to have pushed out the ANI fix last month. We felt certain Microsoft had something needing a patch in March, and it's galling to see that the ANI issue languished when it apparently could have been fixed a few weeks sooner.
---
Tags: Microsoft, Security, Patch, ANI, Exploit
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.
More insider_reports_insider Articles
Insider Reports RSS Feed
|
|