FEATURED VIDEO

Sponsored By:
SLIDE SHOWS
Our list of the most innovative executives of the year spotlights the people that are pushing the envelope with new products and channel programs to bring solution providers to new heights.
Find out which executives made the grade and held their own, despite the great IT downturn of 2009.
Most everyone loves Thanksgiving turkeys. But IT industry turkeys? Not so much. We look at 10 examples of 'turkeys' that have disappointed the tech industry this year.
INSIDE CHANNELWEB

Microsoft Plans Emergency Patch For .ANI Bug


CRN logo By Kevin McLaughlin, ChannelWeb

4:08 PM EDT Mon. Apr. 02, 2007
A week before its monthly Patch Tuesday release, Microsoft plans to release an emergency patch Tuesday for the four-month-old animated cursor file (.ANI) vulnerability in Windows after attacks using the flaw spiked over the weekend.

"From our ongoing monitoring of the situation, we can say that over this weekend attacks against this vulnerability have increased somewhat," wrote Christopher Budd, security program manager at Microsoft's Security Response Center, in a Monday blog post.

The public disclosure of proof-of-concept code and customer feedback has spurred Microsoft researchers to work "around the clock" to test the update, Budd wrote.

Security researchers rushed to offer their assessments on what appears to be most serious security vulnerability of 2007. Websense Security Labs said it's tracking more than 100 Web sites that are spreading the .ANI exploit, most of which are downloading and installing password-stealing code. Researchers from McAfee's Threat Center said they discovered a spam campaign that attempts to drive users to a Web site hosting exploit code.

Researchers from the Chinese Internet Security Response Team (CSIRT) said they've discovered a worm using the .ANI exploit that's spreading.

The worm, which mimics the behavior of the Win32.Fujacks worm, inserts malicious links into .HTML, .ASPX, .HTM, .PHP, .JSP, .ASP and .EXE files, directing users to sites hosting the .ANI exploit, according to a Monday CSIRT bulletin.

Microsoft had originally planned to patch the .ANI flaw as part of its April 10 monthly patch release, but the company was able to speed up the testing process and release a fix ahead of schedule, Budd wrote.

"Due to the increased risk to customers from these latest attacks, we were able to expedite our testing to ensure an update is ready for broad distribution sooner than April 10," Budd wrote.

However, he said it's possible that Microsoft could be forced to delay the release of the patch if the company encounters any unforeseen issues in testing the patch.

 
Channelweb : Promofinder
FEATURED PROMOTIONS
Avnet 0% Lease Promotion
The Avnet Capital Solutions “0% Lease Promotion” has been extended to December 31, 2009! This offering significantly reduces ...
Double Your Money!
Cash Rewards - DOUBLED!
RELATED BLOG >>
Photo
LogLogic takes complex log data and turns it into something manageable.
ADVERTISEMENT




CHANNEL SERVICES >>