Categories: SecuritySoftware

Mozilla Blocks Microsoft Security Add-ons

Mozilla is blocking the use of two Microsoft add-ons installed silently on Windows computers with .NET Framework 3.5 Service Pack 1.

Mozilla is blocking the Microsoft .NET Framework Assistant and Windows Presentation Foundation components in light of a vulnerability that attackers can use to impact Firefox users.

“Because of the difficulties some users have had entirely removing the add-on, and because of the severity of the risk it represents if not disabled, we contacted Microsoft today to indicate that we were looking to disable the extension and plugin for all users via our blocklisting mechanism,” Mike Shaver, vice president of engineering at Mozilla, blogged on 16 Oct. “Microsoft agreed with the plan, and we put the blocklist entry live immediately.”

The vulnerability at the heart of the issue is CVE-2009-2529, covered here in Microsoft’s latest batch of Patch Tuesday bulletins. To exploit the vulnerability in question, all that is needed is for a user to visit a malicious site, Microsoft explained on its Security Research and Defense blog.

“Triggering this vulnerability involves the use of a malicious XBAP (XAML Browser Application),” according to the Microsoft blog. “Please note that while this attack vector matches one of the attack vectors for MS09-061, the underlying vulnerability is different. Here, the affected process is the Windows Presentation Foundation (WPF) hosting process, PresentationHost.exe.

“For Firefox users with .NET Framework 3.5 installed, you may use ‘Tools’-> ‘Add-ons’ -> ‘Plugins,’ select ‘Windows Presentation Foundation,’ and click ‘Disable,'” Microsoft added.

Firefox users who download the Microsoft patch are protected against the vulnerability as well, according to the Microsoft blog.

This is not the first time Mozilla has shown concern for plug-ins from other vendors. Earlier this year, the company decided to warn users if they are using a vulnerable version of Adobe Flash Player plug-in.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Co-op IT System Partly Shutdown After Hack Attempt – Report

A second British high street chain, the Co-op, has been struck by a cyberattack after…

5 hours ago

CEO Pichai Says Google Hopes To Reach Gemini Deal With Apple In 2025

Bad news for OpenAI? Alphabet's Sundar Pichai says Google hopes to reach Gemini AI agreement…

6 hours ago

Cybersecurity Experts Urge Trump To Halt “Political Persecution” Of Chris Krebs

Trump Administration urged to cease its “politically motivated investigation” of former CISA Director Chris Krebs

7 hours ago

UK Unveils Draft Rules For Crypto Industry

UK to align with US on crypto approach, with draft rules for industry that “support…

8 hours ago

Toyota ‘Collaboration’ With Waymo For Autonomous Cars

Preliminary agreement between Waymo and Japanese car giant Toyota for Google's unit pioneering autonomous driving…

9 hours ago

Amazon’s Project Kuiper Launches To Challenge Musk’s Starlink

First launch of Amazon’s Project Kuiper internet satellites takes place, as Jeff Bezos challenge to…

12 hours ago