iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Microsoft Plans To Fix ANI Flaw Early
Search:
[ insider_reports_insider ]

Microsoft Plans To Fix ANI Flaw Early



David Utter
Staff Writer
2007-04-02

SecurityProNews: Insider Reports Insider Reports RSS Feed


An escalation of attacks against Internet Explorer through a vulnerability in the handling of animated cursor files will receive a patch ahead of Microsoft's customary patch date.

Microsoft Plans To Fix ANI Flaw Early
Microsoft Plans To Fix ANI Flaw Early

The malicious ANI exploit we cited last week will receive a needed patch on April 3rd, a week ahead of Patch Tuesday, the informal name for Microsoft's usual day to issue patches. It probably should have been fixed sooner.

Christopher Budd reported the advanced release date on the Microsoft Security Response blog. He noted the company has known about this little drive-by problem for some time:

I'm sure one question in people's minds is how we're able to release an update for this issue so quickly. I mentioned on Friday that this issue was first brought to us in late December 2006 and we've been working on our investigation and a security update since then.

This update was previously scheduled for release as part of the April monthly release on April 10, 2007. Due to the increased risk to customers from these latest attacks, we were able to expedite our testing to ensure an update is ready for broad distribution sooner than April 10.

Microsoft's expedited release comes as more attacks have been sighted in the wild taking advantage of the exploit. Security firm F-Secure reported a half-dozen incidents in China where a worm uses the ANI exploit to spread.

Security pros may arch their eyebrows at Microsoft's quicker response for a couple of reasons. First, they've known about the problem for a few months. Second, they completely skipped the March patch release, something which had not happened for a couple of years.

It might have been a good idea for Microsoft to have pushed out the ANI fix last month. We felt certain Microsoft had something needing a patch in March, and it's galling to see that the ANI issue languished when it apparently could have been fixed a few weeks sooner.

---

AddThis Social Bookmark Button


Tags: , , , ,



About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds