FEATURED VIDEO

Sponsored By:


SLIDE SHOWS
ChannelWeb's Top 25 Execs of 2008 know that reading is fundamental. Here are their picks for books to feed your brain.
There were plenty of high-powered movers and shakers that made a big impact on the channel in 2008. Here's a look at who made our list of the 25 most influential.
It's time again to agonize over what to get the techie in your life. With the holidays closing in fast, here are 25 gift ideas sure to wow any techie.
INSIDE CHANNELWEB
techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Regional Desktop Coordinator
BP seeking Regional Desktop Coordinator in Houston, TX
spacer

Microsoft Plans Emergency Patch For .ANI Bug


CRN logo By Kevin McLaughlin, ChannelWeb
4:08 PM EDT Mon. Apr. 02, 2007
A week before its monthly Patch Tuesday release, Microsoft plans to release an emergency patch Tuesday for the four-month-old animated cursor file (.ANI) vulnerability in Windows after attacks using the flaw spiked over the weekend.

"From our ongoing monitoring of the situation, we can say that over this weekend attacks against this vulnerability have increased somewhat," wrote Christopher Budd, security program manager at Microsoft's Security Response Center, in a Monday blog post.

The public disclosure of proof-of-concept code and customer feedback has spurred Microsoft researchers to work "around the clock" to test the update, Budd wrote.

Security researchers rushed to offer their assessments on what appears to be most serious security vulnerability of 2007. Websense Security Labs said it's tracking more than 100 Web sites that are spreading the .ANI exploit, most of which are downloading and installing password-stealing code. Researchers from McAfee's Threat Center said they discovered a spam campaign that attempts to drive users to a Web site hosting exploit code.

Researchers from the Chinese Internet Security Response Team (CSIRT) said they've discovered a worm using the .ANI exploit that's spreading.

The worm, which mimics the behavior of the Win32.Fujacks worm, inserts malicious links into .HTML, .ASPX, .HTM, .PHP, .JSP, .ASP and .EXE files, directing users to sites hosting the .ANI exploit, according to a Monday CSIRT bulletin.

Microsoft had originally planned to patch the .ANI flaw as part of its April 10 monthly patch release, but the company was able to speed up the testing process and release a fix ahead of schedule, Budd wrote.

"Due to the increased risk to customers from these latest attacks, we were able to expedite our testing to ensure an update is ready for broad distribution sooner than April 10," Budd wrote.

However, he said it's possible that Microsoft could be forced to delay the release of the patch if the company encounters any unforeseen issues in testing the patch.


RATE THIS ARTICLE Worse 1 2 3 4 5 Better
CHANNELWEB MARKETSPACE >> (Sponsored Links)
Channelweb : Promofinder
FEATURED PROMOTIONS
90% OFF Aladdin SafeWord Starter Pack - Act Now!!
Make more money with SafeWord and Aladdin now that we've joined teams. Order a SafeWord Two-Factor Authentication Starter P...
Get More in Q4 from Kaspersky Lab
Sell Kaspersky products and earn dollars for every sale of 10 or more nodes. That’s right! Every sale you make will put extra...
LATEST NEWS >>
December 01, 2008 06:50 PM
December 01, 2008 04:19 PM
December 01, 2008 03:40 PM
December 01, 2008 11:55 AM
December 01, 2008 10:39 AM
RELATED BLOG >>
Photo
The Test Center's most recent threat watch.
ADVERTISEMENT




CHANNEL SERVICES >>