Windows Security Threat - Animated Cursor loophole

rss RSS
Latest post Thu, Jun 12 2008 11:11 AM by Neil Henry (21,259 pts ). 2 replies.
  • Windows Security Threat - Animated Cursor loophole

    Some people love then, others (myself included) hate them. Call me a traditionalist but the animated cursor is an annoyance. For me the good old fashioned mouse pointer does the job just fine. However, for those who have a penchant for animated cursors – BEWARE !!!

    Recently the security of Microsoft’s Windows portfolio has again come under scrutiny, and this time Windows Vista is not spared from the blushes. Microsoft is warning users that the Windows operating system infrastructure code is vulnerable to security breaching through animated cursors manipulation. It is not a common, or widespread problem at present but it has become apparent that the way the OS manages animated cursors can be exploited by program code (malicious program installation) that hacks into web pages and email messages.

    As such users running animated cursors on Windows platforms need to be extremely vigilant when launching specific web pages, clicking on links, viewing email messages or opening attachments. To the unsuspecting user such actions can launch rogue programs that then auto-install malicious code in the form of remote control or spyware. Providing an attacker with access to your system and data.

    The severity of such animated cursor hacks threatens online infrastructure as an attacker can very easily mimic or hack a trusted site, and from there manipulate unsuspecting users to visit a ‘trap site’. Now although to date it has not become a widespread problem, the backdoor coding structure of Windows is such that it will be difficult to close (certainly on XP and below) but more pressing, on Windows Vista.

    That said, PC’s currently running Vista alongside Internet Explorer 7 are immune from such animated cursor attacks, due to the protected mode shield architecture of IE7 which prevents such auto-download / installs. Now call me a skeptic but doesn’t this all just sound a little too convenient for Microsoft? Its OK if you use 'our' OS and 'our' web browser, but if you don't then you might have a problem. I’ll let you decide whether that’s scare mongering, a direct threat to get you to use Vista AND Internet Explorer 7 or if this threat is indeed a serious issue that could destabilize your PC's integrity. But as things stand all we know is this, Windows users with animated cursors running 3rd party web browser software (i.e. Firefox or Opera) are at risk.

    So if you absolutely MUST HAVE that fancy little cursor dancing its way around your screen, then this is all worth considering the next time you see a web page or email that looks suspicious. Otherwise, stick with the good old default mouse pointer and run Vista, XP, 98 or whatever, to your hearts content. That way you won’t be threatened to move away from your personal preference of email and web browser software. Personally I’ll stick to Vista and Firefox and trust Zone Alarm to pick up any pieces.

    Published by Neil Henry (21,259 pts ) on May 23 2008, 05:07 AM to
    Windows Platform Discussions
  • Re: Windows Security Threat - Animated Cursor loophole

    In reply to

    There is, BTW, a patch for this vulnerability. 

    Published by Bill Bunter (6,644 pts ) on May 23 2008, 12:22 PM to
    Windows Platform Discussions
  • Re: Windows Security Threat - Animated Cursor loophole

    In reply to

     ...and it works a charm. Shame they can't resolve security and speed like they can mouse pointer architecture!

    Published by Neil Henry (21,259 pts ) on Jun 12 2008, 11:11 AM to
    Windows Platform Discussions
showing 1-3 of 3    

Windows Platform
Enter your email to subscribe to the Windows Newsletter
 

Bright Hub is looking for talented writers to contribute to one of the fastest growing communities online. If you have something bright to say, say it here! Learn more here.

 
Search Prompt