Patches - Windows ANI Workaround Updated as Exploit Mutates - eWeek Security Watch

Windows ANI Workaround Updated as Exploit Mutates

Written By
Lisa Vaas
Lisa Vaas
Apr 3, 2007
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

eEye has updated its workaround for the Windows animated cursor flaw—a flaw that some are claiming is responsible for the first real remote code execution exploit on Vista.

The update was released in response to a variant on the original attack that bypasses the security firm’s original workaround patch.

The updated eEye patch is available here.

eEye’s workaround is temporary, meant to tide users over until Microsoft comes out with its official patch. Microsoft has jumped its regular patch schedule to release its fix for the ANI flaw and will deliver that patch on Tuesday, April 3.

Microsoft managed to rush the patch out only after McAfee made it public last week. Microsoft has made it clear that it has known about the flaw since December. The company over the weekend posted a list of answers to frequent ANI-related questions it has been receiving, one of which said that the company was first alerted to the Windows animated cursor vulnerability on Dec. 20 by a security researcher at Determina.

In Microsoft’s statements regarding the ANI attack, the company has grumbled about irresponsible disclosure: a not-too-well-hidden rebuke to McAfee.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.