Here's the scoop on the Windows animated cursor bug

Microsoft is promising an early patch for the ANI vulnerability

When a major vulnerability affecting every flavor of Windows -- including Vista -- breaks, it only seems like chaos ensues. Okay, so it is chaos. Witness the so-far short-lived flaw in Windows' animated cursors (ANI), which picked up enough steam over the weekend to power a turbine or two. IT staff, small business users and consumers have been trying to figure out which way is up, and whether this is a Big Deal or just another security industry siren blaring in the background. This FAQ on the flaw, explains what it is, which machines are at risk and what you can do to protect yourself.

What's the problem, anyway? A critical flaw in User32.dll, specifically in the code of that Windows .dll that loads animated cursor (.ani) files, which are used to trick out the cursor, changing it from a simple pointer to a short animation. Microsoft, for example, sometimes includes animated cursors in its optional visual theme downloads. Exploits targeting the bug can use ANI files to run malicious code on a victimized PC, infecting it with spyware, stealing identity information or adding it to a botnet of hijacked systems.

When did this pop up? Microsoft says it was first notified in late December 2006 by researchers at Determina, but others -- including Marc Maiffret of eEye Digital Security -- point out that the vulnerability is very similar to one patched in January 2005 that also affected cursor files. It wasn't until last week -- March 28, to be exact -- that attacks using the exploit were spotted in the wild (by McAfee) and reported to Microsoft's Security Response Center (MSRC).

What versions of Windows are vulnerable? This is the cropper, isn't it? One of the things that makes the ANI bug so dangerous is that it affects every still-supported edition of Windows, including Windows 2000 SP4, XP SP2, Server 2003 (up to SP2), and even Vista. Both 32- and 64-bit versions are at risk.

What about Linux or Mac systems? Are they at risk, too? Hahahahahaha. Sorry. Nope.

Are hackers using the vulnerability? Funny. China's Internet Security Response Team (CISRT) warned over the weekend that a worm exploiting ANI was in the wild. Symantec tagged the worm as Fubalca, while other security companies -- no surprise here -- applied different monikers. McAfee, for instance, calls it Fujacks.aa, while Computer Associates labeled it MSA-935423!exploit. Nothing like consistency. Other reports have cited one or more spam runs that include links to malicious sites hosting an ANI exploit, while the newest information from Websense Inc. is that there are at minimum 150 Web sites circulating the attack. So the short answer, unfortunately, is yes.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?