You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft in a fix over cursor patch

More haste, less speed...

Tags: microsoft, cursor, patch

By Joris Evers

Published: 5 April 2007 08:54 GMT

Installing Microsoft's Tuesday patch for a "critical" Windows vulnerability is causing trouble for some users.

Microsoft broke with its monthly patch cycle on Tuesday to repair a bug in the way Windows handles animated cursors. Cyber crooks had been using the hole since last week to attack Windows PCs. But the fix is not compatible with software that runs audio and networking components from Realtek Semiconductor, some Windows users have found.

Dave House, a reader of silicon.com sister site CNET News.com, wrote in an email: "Apparently the update is not compatible with Realtek. We lost all Ethernet and audio functions. Removing the update and doing system restores brought the systems back."

Microsoft is aware of problems with Realtek's audio software. In fact, it knew about them before releasing the fix and published a support article with the security bulletin. An additional update is available from Microsoft to remedy the problem, according to the company's website. Microsoft is not aware of networking issues, a representative said.

The audio problem occurs on Windows XP PCs that have the Realtek HD Audio Control Panel installed, Microsoft said. The application may not start after the patch is applied and Windows may display an error message, the company said.

Microsoft consciously released the cursor flaw patch despite the compatibility problem, Mike Reavey, a Microsoft Security Response Center staffer, wrote on a corporate blog. The company tested the fix throughout February and March and eliminated many problems, he wrote.

He added: "At one point our testing had uncovered over 80 potential issues with the update that were investigated and resolved... at the time of release, only one minor quality issue was known."

The cursor vulnerability is one of seven flaws addressed by Microsoft's Tuesday patch - three of them also affect Vista. Cyber crooks moved quickly to exploit the cursor hole. Security company Websense has spotted hundreds of websites that try to use the bug to compromise PCs, as well as an email spam campaign with links to the malicious sites.

Microsoft plans to issue additional fixes next week on its regular monthly patch day, the company said.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...


  • Jobs
Web Applications Vulnerability Tester

Title: Web Applications Vulnerability Tester / Penetration Tester Salary: market rates but probably 40k to 60k Company: online / ecommerce company ...

AV Field Integration Engineer

AV Field Integration Engineer My client are a leading Audio Visual IT reseller based in Berkshire/Hampshire and are seeking an AV Field Service ...

Software Developer - SharePoint

Manage bug fix requests; troubleshoot, develop, test, and document as necessary in accordance with existing procedures. This international Law Firm ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: