3/30/2007

EEye publishes fix for Windows zero-day vulnerability

Filed under: — Aviran Mordo @ 9:43 am

With online criminals exploiting an unpatched flaw in Windows, security vendor eEye Digital Security has come forward with an unofficial fix for the problem.

The unofficial temporary patch, published early Friday, fixes a bug in the way Windows processes Animated Cursor files, which are used to create cartoon-like cursors in Windows. Security researchers at McAfee first reported the bug on Wednesday evening, saying that it has been used in Web-based attacks.

Microsoft has said that it will eventually fix the problem and it generally recommends that users avoid this type of third-party fix for its products. But in the past, similar patches from eEye and others have been downloaded by tens of thousands of Windows users, unwilling to wait for Microsoft’s updates.

Microsoft’s next set of security patches are due April 10, but the software giant has not said whether or not that release will include a fix for the Animated Cursor problem.

 

Leave a Reply

You must have Javascript enabled in order to submit comments.

All fields are optional (except comment).
Some comments may be held for moderation (depends on spam filter) and not show up immediately.
Links will automatically get rel="nofollow" attribute to deter spammers.

Powered by WordPress