KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

Windows 7 RTM Build 7260 download x32 and x64 HERE !

How to activate Windows 7 RC build 7229, 7231 and olders


Vista Can Be Taken Down by an Animated Cursor

section: windows, for your questions: KezNews forum, 30.3.2007

    Tip: Click here to update all your PC's outdated drivers

In what could be the most embarrassing exploit to impact Windows Vista since its commercial launch in January, security engineers at McAfee's Avert Labs confirmed today - and posted the video to prove - that the operating system can be caused to enter an interminable crash-restart-crash loop, by means of a buffer overflow triggered by nothing more than a malformed animated cursor file.




It isn't even a new exploit, as researchers with eEye discovered in January 2005. At that time, Microsoft acknowledged it affected versions of the operating system from the first edition of Windows 98 through to early releases of Windows XP, though it stated at the time XP SP1 was unaffected.

But apparently after researching field reports of limited attacks, Avert Labs discovered an apparently similar exploit using .ANI files impacts XP SP2 and Vista as well, as well as Windows 2000 SP4 and versions of Windows Server 2003 from the initial release through to SP1. Avert Labs stated XP SP1 and versions since were unaffected, though Microsoft warned the exploit does affect XP SP2.

If both firms' accounts are correct, Microsoft may have fixed the problem with XP SP1 in 2005, and inadvertently un-fixed it sometime afterward.

Avert Labs' video of the incident, posted to YouTube, shows a Vista system wherein the test file apparently trying to load the custom animated cursor. When the operating system detects a crash, it first tries to save vital data prior to a restart sequence - one of Vista's newer features. It then informs the user that Windows Explorer has crashed.

But in trying to restart Explorer, the restarting crashes itself, sending Vista into a tailspin from which the only escape appears to be the off button.

The mouse input routines in Windows are designed with the intention of being relatively failsafe. That's why when the system appears to hang, you can often still move your mouse pointer. As I've personally witnessed on many occasions with Windows XP, it's possible for a smaller OEM's mouse driver - often an unsigned one - to trigger a similar tailspin loop that crashes Windows Explorer repeatedly. In Windows, a lot depends on the mouse pointer's very existence.

So if a customization feature can impact the mouse pointer's ability to function, the integrity of the entire system can be jeopardized. With my own systems, drivers and services that are unfriendly to one another - such as Stardock's CursorXP animation program trying to co-exist with a Synaptics Pointing Device driver on a notebook with ATI Mobility Radeon 9600 graphics - can trigger an Explorer tailspin.

What I'm calling the "tailspin" is nothing new. What is very disturbing about this revelation, however, is that it can be triggered by nothing more than Microsoft's own operating system software and processes.

McAfee reports this exploit is being utilized in the wild, and Microsoft today issued its boilerplate language warning users not to open e-mail attachments they don't recognize.

View: KezNews Discussion - Vista Can Be Taken Down by an Animated Cursor

  >> Click Here to Run a Free Scan for PC Errors <<

send email Send link 2 friend  |  Permalink
<< previouse article
Frameworkx WinSiM
next article >>
How's the Reception at Channel 9?

MORE RELATED ARTICLES:
How to Install Vista Language Packs MUI on all versions of Vista + video tutorial || x64 Vista SP2 JPG Rendering Performance Inferior to x86 Vista SP2's || New Vista AutoPatcher - Vista update toolkit Alpha || Vista SP1 Rolling Over for Vista SP2 || Vista RTM vs. Vista SP2

Comments(12)

The Link to the Video

By Dan on 30.03.2007 - 09:03
http://www.youtube.com/watch?v=hf0s0vk7j6i


That's trully sad

By unkchaos on 30.03.2007 - 14:03
i just watched the video and found it f-ing hilarious. i didn't expect some deadly tailspin like that can be done sooo easily especially with windows vista's hype about their so called "wicked security". i'd laugh if i find apple making a commercial base on that situation lol.

LINK OFF

By bigpinto on 30.03.2007 - 15:03
youtube link off

Repost the video please

By marimol on 30.03.2007 - 16:03
the video is down. please re-upload

Found it

By marimol on 30.03.2007 - 16:03
ok, i found it somewhere else. that was great!

http://www.avertlabs.com/research/blog/?p=233

lol...awesome

By sup on 30.03.2007 - 20:03
that trully is sad. amazing video though. i laughed my @$$ off for about a minute. so much for vista's vaunted security.

Funny Video

By Funny Bugy Bunny on 30.03.2007 - 22:03
it's a small bugs world after all :)

re: Funny Video

By Scarabee on 30.03.2007 - 22:03
lmao meh

not just Vista

By Vista Fan on 31.03.2007 - 00:03
hey guys, have been following this story and microsoft's reaction, its all versions of windows that use ie6,7 - they said it also affects email and if you use firefox with addins you might be ok, but take care until microsoft gets a hotfix.

also XP home

By xp dude on 31.03.2007 - 00:03
this happened to me last night lol - using xp home, cannot belive this problem is here, the video is funny :)

Video down

By Dunge on 31.03.2007 - 04:03
video got taken down?! are there any copyright thing on it or what?

Nevermind..

By Dunge on 31.03.2007 - 04:03
nevermind, i must learn to read :)


No new comments are allowed for this article.

For your questions use our KezNews Discussion - Vista Can Be Taken Down by an Animated Cursor