Patch for ANI Cursor Vulnerability

Patch for ANI Cursor Vulnerability Screenshot An unspecified vulnerability exists within Microsoft Windows which may possibly allow for a remote attacker to execute arbitrary code under the context of the logged in user.

Developer:   eEye Digital Security
      software by eEye Digital Security →
Price:  0.00
License:   Freeware
File size:   0K
Language:   
OS:   Windows XP/Vista (?)
Rating:   0 /5 (0 votes)

An unspecified vulnerability exists within Microsoft Windows which may possibly allow for a remote attacker to execute arbitrary code under the context of the logged in user.

This vulnerability requires user interaction by viewing a malicious Windows animated cursor (.ANI) file. .ANI files are commonly used by web developers to display custom cursor animations to enhance web-site experiences.

The most potent attack method is by embedding a malicious .ANI file within an HTML web page. Doing so allows the vulnerability to be exploited with minimal user interaction by simply coaxing a user to follow a hyperlink and visit a malicious web site. Other exploit vectors exist including Microsoft Office applications since they also rely on the same .ANI processing code, making e-mail delivery also a potent threat by using Microsoft Office attachments.

Since .ANI processing is performed by USER32.dll and not the attack vector application itself, all attack vectors have the potential to use a similar exploit with similar address offsets targeted at Windows directly, allowing for a very reliable exploit.

Users who install this patch should note:
• This patch is a temporary fix and should be removed before the official Microsoft patch is installed.
• It is recommended that users test this patch thoroughly before installing.
• This patch only supports Windows 2, Windows XP, Windows Server 2003, and Windows Vista.
• This patch will not work on x64 or Itanium architectures.
• To install silently run this command:
WindowsAnimationPatchSetup.exe /qn
• To uninstall silently run this command:
msiexec /qn /x {DFEF2523-72D0-483F-A1C2-FC29B71B166A}
• This patch includes a checker that will uninstall itself when it detects a Microsoft patch has been installed. To disable the checker, run the installation with this command line (command is case-sensitive): WindowsAnimationPatchSetup.exe NOCHECKER=1

tags this patch  this command  silently run  run this  microsoft patch  windowsanimationpatchsetup exe  user interaction  web site  microsoft office  ani processing  ani file  

Patch for ANI Cursor Vulnerability screenshot


Download Patch for ANI Cursor Vulnerability

 Download Patch for ANI Cursor Vulnerability


Similar software

Patch for ANI Cursor Vulnerability Patch for ANI Cursor Vulnerability
eEye Digital Security

An unspecified vulnerability exists within Microsoft Windows which may possibly allow for a remote attacker to execute arbitrary code under the context of the logged in user.

eEye’s Temporary Workaround 1.0 eEye’s Temporary Workaround 1.0
eEye Digital Security

eEye Digital Security is advising customers to the existence of exploit code that targets a critical security vulnerability in Microsoft Internet Explorer.

Determina Fix for CVE-2006-1359 1.0 Determina Fix for CVE-2006-1359 1.0
Determina

Based on the same technology used in the VPS LiveShield product, Determina has engineered a standalone fix that provides free and immediate protection to users worldwide that need to protect systems from related attacks until such time as Microsoft issues its own patch.

MSI Patch Builder 1.0 MSI Patch Builder 1.0
MSI Patch Builder

MSI Patch Builder compliments Microsoft Visual Studio Setup Projects by providing a quick and simple way to create MSI Patches.

Universal Msn Polygamy 1.0 Universal Msn Polygamy 1.0
VulturZ Inc.

This Patch allows you to run multiple Msn's at 1 time.

Patch Creator 2.8 Patch Creator 2.8
Funduc Software

With Patch Creator you can create patches for updating registered versions of your software.

PATCHifier 1.0 PATCHifier 1.0
TEFASOFT

PATCHifier is a very customizable patch organizer/installer for the Windows platform.

DCOMbobulator 2.01 DCOMbobulator 2.01
GRC

What is DCOM? Windows employs a component-based system to help programmers manage Windows' complexity.

WinRAR 3.40 GUI Patch 1.0 WinRAR 3.40 GUI Patch 1.0
Neowin

Made by Neowin's own SentientPC, the WinRAR GUI Patch provides users of WinRAR 3.

Warez Acceleration Patch 5.0.8 Warez Acceleration Patch 5.0.8
Download Boosters

Warez P2P Acceleration Patch is a useful add-on for Warez P2P Client.