Exploit for "Zero-Day" Vulnerability Detected by Microsoft

For Firefox users

You might want to read this.

Firefox ANI exploit on the way - no protected mode

http://blogs.zdnet.com/Ou/?p=461

Spooky :o :o

Only George Ou could use a MS bug to bash Firefox. ::slight_smile:

Isn’t the fix for this out today anyway?

I Just spoke with Opera support team & they said that Opera is safe to protect against ANI Exploit… for now… :-\ ::slight_smile: ::slight_smile:

Thanks Bob!

I checked a few moments ago and it wasn’t available in the UK, but I’ll try again later.

I checked earlier this morning and it wasn’t available here. Re-checked after I saw your post
and it was there. Thanks :slight_smile:
A reboot is required after this update.

Security Update for Windows XP (KB925902)
just got it…
Microsoft released the below security bulletin to address a CRITICAL vulnerability issue in Windows:

MS07-017 - Vulnerabilities in GDI Could Allow Remote Code Execution (925902)

The security update applies to:
Microsoft Windows 2000 Service Pack 4
Microsoft Windows XP Service Pack 2
Microsoft Windows XP 64-Bit Edition Version 2003 (Itanium)
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003
Microsoft Windows Server 2003 for Itanium-based Systems
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 Service Pack 2
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems and Microsoft Windows Server 2003 with SP2 for Itanium-based Systems
Microsoft Windows Server 2003 with SP2 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition
Microsoft Windows Server 2003 x64 Edition Service Pack 2
Microsoft Windows Vista

References:
MS Advisory 935423: http://www.microsoft.com/technet/security/...ory/935423.mspx
MS Security Bulletins for end-users: http://www.microsoft.com/athome/security/u...ins/200704.mspx
MS Security Bulletins for IT Pro: http://www.microsoft.com/technet/security/...n/ms07-apr.mspx
MS Response Center Blog: http://blogs.technet.com/msrc/default.aspx
MS KB925902: http://support.microsoft.com/?kbid=925902
MS Security Bulletin: http://www.microsoft.com/technet/security/...n/ms07-017.mspx

Note:
Microsoft NEVER send security updates via e-mail. Download only the updates using Windows Updates, Microsoft Download Center websites or Automatic Updates functionality in Windows.

Oops! What does this mean? ???

http://donaldbroatch.users.btopenworld.com/dllerror.png

Google rthdcpl.exe and you’ll find it is an infection ::slight_smile:

This is all I could find.

Description:
rthdcpl.exe is a process belonging to the Realtek HD Audio Control Panel and is bundled alongside Realtek sound cards and audio hardware. This program is a non-essential process, but should not be terminated unless suspected to be causing problems

Can you get an update?

This is why Microsoft takes so long to issue fixes- if it rushes them out like today, it’ll bugger up something else at the same time it fixes the problem.

:frowning:

Hm, interesting. Yes, (the updated) user32.dll now has the same base address as hhctrl.ocx. I wouldn’t think it should be a problem, however… that’s why they are DLLs - they are relocatable.

Maybe the system doesn’t like to relocate its system libraries… but I’d expect user32.dll to be loaded before hhctrl.ocx anyway…
Strange.

I’ve got the same process, and so far no problems (Vista HP).

I have exactly the same problem too! and i do have the realtek audio as audio driver, for now i just restored the computer back to before the update, but i dont know how to fix this :cry:

Just found this:

http://support.microsoft.com/?kbid=925902

Have you tried the hotfix Frank? does it work?

thanks for the info freewheelinfrank…didn’t get the error as some of you got since i don’t have the realtek audio as audio driver on both of my computers…they must of rush this patch out and now they have another problem-way to go again microsoft

CAUSE This problem may occur after you install security update 925902 (MS07-017) and security update 928843 (MS07-008). The Hhctrl.ocx file that is included in security update 928843 and the User32.dll file that is included in security update 925902 have conflicting base addresses. This problem occurs if the program loads the Hhctrl.ocx file before it loads the User32.dll file.
RESOLUTION Hotfix information A supported hotfix is now available from Microsoft. However, it is intended to correct only the problem that is described in this article. Apply it only to systems that are experiencing this specific problem. This hotfix may receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next Windows XP service pack that contains this hotfix.

To resolve this problem immediately, contact Microsoft Customer Support Services to obtain the hotfix. For a complete list of Microsoft Customer Support Services telephone numbers and information about support costs, visit the following Microsoft Web site:
http://support.microsoft.com/contactus/?ws=support (http://support.microsoft.com/contactus/?ws=support)
Note In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The usual support costs will apply to additional support questions and issues that do not qualify for the specific update in question.

Translation:

CAUSE
We goofed up.

RESOLUTION
We have a patch to fix the goof up, but it may goof up your computer even more, so we recommend you wait for the next blue moon XP service pack, or contact customer support where we will tell you how much we’re going to charge for fixing our goof up.

They’re actually going to CHARGE to fix a problem THEY caused?? ??? ???