Mozilla to Disable ANI Exploits’ Path of Entry

執筆者
Lisa Vaas
Lisa Vaas
Published: Apr 5, 2007
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

The Mozilla Foundation is looking at disabling support for the Windows animated cursor format as a workaround for the ANI vulnerability that has left Windows systems open to exploit and complete takeover for the past week.

Firefox users who use automatic update should get an update notification for the workaround. Users who have turned off update notification can use the “Check for Updates…” item on Firefox’s Help menu.

Microsoft posted a security bulletin with patches for the critical ANI flaw on Tuesday. Microsoft, along with Firefox and security researchers, has urged Windows users to patch immediately.

Mozilla Vice President of Engineering Mike Schroepfer told eWEEK that the workaround may come in the next scheduled security release of Firefox.

Firefox lacks a low-privilege mode similar to Microsoft Windows Vista’s Protected Mode—a condition that Determina security researcher Alexander Sotirov demonstrated can be used to overwrite files on an exploited system. Windows systems that lack the MS 07-017 patch and are running either Firefox or Internet Explorer in Protected Mode are susceptible to a remote attacker being able to access and read files on a victimized system, but Protected Mode does prevent file overwrite.

Still, anybody who was running anything but Vista was a sitting duck prepatch, and given that not many are as yet running Vista, that meant most Windows users.

Nevertheless, Schroepfer pointed out, Firefox users have been safer than IE users, given that the ANI flaw is harder to exploit. “On Firefox, [exploiting the vulnerability] takes quite a lot more work than on IE,” he said. “It’s not as obvious where the feature is used on Firefox.”

Firefox will likely still use animated cursors locally if users already have them on their systems, Schroepfer said. Mozilla will disallow loading the ANI files remotely, given that remote access is where the vulnerability lies and is how exploits have been succeeding.

Mozilla has in the past looked into a low-privilege mode, a la Protected Mode on Windows. But, Schroepfer said, it’s “fairly complicated” to program in that mode. Microsoft is the only application maker that includes it, he pointed out.

Still, “It’s something we’re interested in doing,” he said.

As always, Mozilla is focused on reducing the attack surface of Firefox in general, Schroepfer said. That includes not loading ActiveX, for example. The animated cursor vulnerability is a case in point: Mozilla will reduce the amount of Windows code used in Firefox in order to shrink its attack surface.

Advertisement

“We’re still focused on reducing attack service in general,” Schroepfer said.

Lisa Vaas

Lisa Vaas

Content Writer

Lisa Vaas is News Editor/Operations for eWEEK.com and also serves as editor of the Database topic center. She has focused on customer relationship management technology, IT salaries and careers, effects of the H1-B visa on the technology workforce, wireless technology, security, and, most recently, databases and the technologies that touch upon them. Her articles have appeared in eWEEK's print edition, on eWEEK.com, and in the startup IT magazine PC Connection.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。