1.

Solve : Vista taken down by animated cursor?

Answer»

In what could be the most embarrassing exploit to impact Windows Vista since its commercial launch in January, SECURITY engineers at McAfee's Avert Labs confirmed today - and posted the video to prove - that the operating SYSTEM can be caused to enter an interminable crash-restart-crash loop, by means of a buffer overflow triggered by nothing more than a malformed animated cursor file.

http://www.betanews.com/article/Vista_Can_Be_Taken_Down_by_an_Animated_Cursor/1175201875This reminds me of:
McAfee reports that Windows Accessibility Feature "sticky keys" is an exploit that was never fixed in the release of Vista. Someone could trick a user into downloading a replacement file for the sticky key program, and get them to enable it, making certain keys trigger events.
(this was a summary)
A summary reply to a member of the news article provider stated that the same thing could be accomplished by replacing any .exe file in the Windows folder. (Eg: Lets just remove notepad.exe and replace it with our own virused version)

Malfunctioning... yeah right.
This is an equivelant of the following:
lets all find win.com in the Windows directory
open it with Notepad
and take a whole chunk of the CODE out
restart the computer, and see what happens!!!


In my own personal OPINION, McAfee and some other antivirus companies are throwing a tantrum.
Microsoft is considering closing off kernal.exe to all applications. (Including Antivirus)
McAfee doesent like this... they wouldent be able to "protect" the ALREADY locked to everything Kernal.exe file. (If its protected, then why would a virus infect it?!?!)

http://www.msnbc.msn.com/id/17915077/

Microsoft issuing security patch-

Attacks using the flaw related to cursor animation files used by Windows



Discussion

No Comment Found