Categories: SecuritySoftware

Mozilla Blocks Microsoft Security Add-ons

Mozilla is blocking the use of two Microsoft add-ons installed silently on Windows computers with .NET Framework 3.5 Service Pack 1.

Mozilla is blocking the Microsoft .NET Framework Assistant and Windows Presentation Foundation components in light of a vulnerability that attackers can use to impact Firefox users.

“Because of the difficulties some users have had entirely removing the add-on, and because of the severity of the risk it represents if not disabled, we contacted Microsoft today to indicate that we were looking to disable the extension and plugin for all users via our blocklisting mechanism,” Mike Shaver, vice president of engineering at Mozilla, blogged on 16 Oct. “Microsoft agreed with the plan, and we put the blocklist entry live immediately.”

The vulnerability at the heart of the issue is CVE-2009-2529, covered here in Microsoft’s latest batch of Patch Tuesday bulletins. To exploit the vulnerability in question, all that is needed is for a user to visit a malicious site, Microsoft explained on its Security Research and Defense blog.

“Triggering this vulnerability involves the use of a malicious XBAP (XAML Browser Application),” according to the Microsoft blog. “Please note that while this attack vector matches one of the attack vectors for MS09-061, the underlying vulnerability is different. Here, the affected process is the Windows Presentation Foundation (WPF) hosting process, PresentationHost.exe.

“For Firefox users with .NET Framework 3.5 installed, you may use ‘Tools’-> ‘Add-ons’ -> ‘Plugins,’ select ‘Windows Presentation Foundation,’ and click ‘Disable,'” Microsoft added.

Firefox users who download the Microsoft patch are protected against the vulnerability as well, according to the Microsoft blog.

This is not the first time Mozilla has shown concern for plug-ins from other vendors. Earlier this year, the company decided to warn users if they are using a vulnerable version of Adobe Flash Player plug-in.

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Share
Published by
Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Google Consolidates DeepMind And AI Research Teams

AI push sees Alphabet's Google saying it will consolidate its AI teams in its Research…

2 hours ago

Apple Pulls WhatsApp, Threads From China App Store

Beijing orders Apple to pull Meta's WhatsApp and Threads from its Chinese App Store over…

5 hours ago

Intel Foundry Assembles Next Gen Chip Machine From ASML

Key milestone sees Intel Foundry assemble ASML's new “High NA EUV” lithography tool, to begin…

10 hours ago

Creating Deepfake Porn Without Consent To Become A Crime

People who create sexually explicit ‘deepfakes’ of adults will face prosecution under a new law…

1 day ago

Google Fires 28 Staff Over Israel Protest, Undertakes More Layoffs

Protest at cloud contract with Israel results in staff firings, in addition to layoffs of…

1 day ago