Post Reply 
Vista Can Be Taken Down by an Animated Cursor
Author Message
dasme
eXemplar paraDigm

Posts: 818.1976
Threads: 147
Joined: 20th Jan 2007
Reputation: -5.71592
E-Pigs: 7.6993
Offline
Post: #1
Vista Can Be Taken Down by an Animated Cursor
[frame]Quote
In what could be the most embarrassing exploit to impact Windows Vista since its commercial launch in January, security engineers at McAfee’s Avert Labs confirmed today - and posted the video to prove - that the operating system can be caused to enter an interminable crash-restart-crash loop, by means of a buffer overflow triggered by nothing more than a malformed animated cursor file.

It isn’t even a new exploit, as researchers with eEye discovered in January 2005. At that time, Microsoft acknowledged it affected versions of the operating system from the first edition of Windows 98 through to early releases of Windows XP, though it stated at the time XP SP1 was unaffected.

But apparently after researching field reports of limited attacks, Avert Labs discovered an apparently similar exploit using .ANI files impacts XP SP2 and Vista, as well as Windows 2000 SP4 and versions of Windows Server 2003 from the initial release through to SP1. Avert Labs stated XP SP1 and versions since were unaffected, though Microsoft warned the exploit does affect XP SP2.

If both firms’ accounts are correct, Microsoft may have fixed the problem with XP SP1 in 2005, and inadvertently un-fixed it sometime afterward.

Avert Labs’ video of the incident, posted to YouTube, shows a Vista system wherein the test file apparently trying to load the custom animated cursor. When the operating system detects a crash, it first tries to save vital data prior to a restart sequence - one of Vista’s newer features. It then informs the user that Windows Explorer has crashed.

But in trying to restart Explorer, the restarting crashes itself, sending Vista into a tailspin from which the only escape appears to be the off button.

The mouse input routines in Windows are designed with the intention of being relatively failsafe. That’s why when the system appears to hang, you can often still move your mouse pointer. As I’ve personally witnessed on many occasions with Windows XP, it’s possible for a smaller OEM’s mouse driver - often an unsigned one - to trigger a similar tailspin loop that crashes Windows Explorer repeatedly. In Windows, a lot depends on the mouse pointer’s very existence.

So if a customization feature can impact the mouse pointer’s ability to function, the integrity of the entire system can be jeopardized. With my own systems, drivers and services that are unfriendly to one another - such as Stardock’s CursorXP animation program trying to co-exist with a Synaptics Pointing Device driver on a notebook with ATI Mobility Radeon 9600 graphics - can trigger an Explorer tailspin.

What I’m calling the “tailspin

[Image: unicef320x41thumbnail.gif]

[Image: bizsparkstartup.jpg]
02/04/2007 07:19 AM
Visit this user's website Find all posts by this user Quote this message in a reply
YoYoBallz
L4YoY0s

Posts: 6,057.4567
Threads: 644
Joined: 3rd Mar 2007
Reputation: 15.01961
E-Pigs: 13327.7533
Offline
Post: #2
RE: Vista Can Be Taken Down by an Animated Cursor
Wow.... Thank god my vista don't do this..... but i think my firends might..... ill have to look into this. thanks for posting this :)

<Myth0s> i love boys
-------------------------------------------------------------------
I Go To Earth When Mars Is Boring.
-------------------------------------------------------------------
¿ʞɔпɟ əɥʇ ʇɐɥʍ I was first EPerson to have upside down title.
-------------------------------------------------------------------
02/04/2007 07:31 AM
Find all posts by this user Quote this message in a reply
beaner2k6
∞©∞

Posts: 2,523.4281
Threads: 62
Joined: 1st Mar 2007
Reputation: 1.65351
E-Pigs: 73.7237
Offline
Post: #3
RE: Vista Can Be Taken Down by an Animated Cursor
hehe glad i don't have vista

[Image: beaner2k6.jpg]
[Image: 218ohu.jpg]
[Image: newbitmapimage3aj5.png]
[Image: beaner2k6.png]
02/04/2007 10:16 AM
Find all posts by this user Quote this message in a reply
ZiNgA BuRgA
Smart Alternative

Posts: 17,022.2988
Threads: 1,174
Joined: 19th Jan 2007
Reputation: -1.71391
E-Pigs: 446.1274
Offline
Post: #4
RE: Vista Can Be Taken Down by an Animated Cursor
Meh, there's 1000s of ways to stuff up an OS.  I'd thinnk it'd be pretty hard for the average user to install such a cursor though - the main.cpl would probably crash as soon as you'd try to set it (I imagine that they set the cursor through other means?).
02/04/2007 03:22 PM
Visit this user's website Find all posts by this user Quote this message in a reply
michaelp
s0ny d0minator

Posts: 1,009.4190
Threads: 100
Joined: 19th Jan 2007
Reputation: -1.92737
E-Pigs: 12.5158
Offline
Post: #5
RE: Vista Can Be Taken Down by an Animated Cursor
lol, an animated cursor

microsoft got some spalling to do

[Image: michaelp3.png]
02/04/2007 04:42 PM
Visit this user's website Find all posts by this user Quote this message in a reply
sticky
Way Of Destruction 33

Posts: 719.3800
Threads: 25
Joined: 16th Mar 2007
Reputation: -1.78625
E-Pigs: 11.3336
Offline
Post: #6
RE: Vista Can Be Taken Down by an Animated Cursor
ms got pwnd
02/04/2007 06:47 PM
Find all posts by this user Quote this message in a reply
Apatheticloser
Existential Entity

Posts: 18.1089
Threads: 1
Joined: 31st Mar 2007
Reputation: 0
E-Pigs: 0.5530
Offline
Post: #7
RE: Vista Can Be Taken Down by an Animated Cursor
haha, this is lame.
04/04/2007 02:54 AM
Find all posts by this user Quote this message in a reply
Post Reply 


Forum Jump:


User(s) browsing this thread: 3 Guest(s)

 Quick Theme: