Barney's Blog

Blog archive

Microsoft Issues Zero-Day Warning, Fix-It Tool for 'Shortcut' Flaw

On Friday, Microsoft issued a zero-day (a.k.a. "It's here!") warning about a security flaw that can allow malicious code to get through to Windows desktops and servers (including Windows 7 and Windows Server 2008 R2) via "specially crafted" shortcut icons on attached devices such as USB drives.

Although an official patch has yet to arrive, Redmond yesterday released a so-called "Fix-it" tool that can implement the recommended workaround (disabling shortcut files) for you; the support page (KB338619) also offers instructions for doing the steps manually.

A complete list of the affected software is available on the security advisory here.

The flaw is associated with the spread of the "Stuxnet worm." More information on the underlying Stuxnet malware is available here.
-- By Becky Nagel

Posted by Becky Nagel on July 21, 2010 at 11:53 AM


Featured

  • Mixed-Reality Platform Microsoft Mesh Unveiled at Ignite

    The Ignite virtual conference put much of the spotlight on Microsoft Mesh, a new Azure-based platform for building "cross-platform mixed reality apps."

  • The 2021 Microsoft Product Roadmap

    From Windows 10X to the next generation of Microsoft's application server products, here are the product milestones coming down the pipeline in 2021.

  • 2021 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss.

  • Azure Active Directory B2C Service Goes Up to 'Four Nines'

    Microsoft recently announced an upcoming increase in the Azure Active Directory B2C service-level agreement (SLA).