By Thilak October 18, 2009

Microsoft’s Plug-in puts Firefox Users at Risk

Back in February, Microsoft silently slipped Windows Presentation Foundation plugin into Firefox without user’s consent. This plugin came along with .NET Framework 3.5 Service Pack 1 and was installed in IE as well as Firefox via Windows Update.

firefox-wpf-add-on

It has now been discovered that the code in the plugin can cause a very serious vulnerability in Firefox, which will potentially expose users to "browse and you’re owned" attacks. According to Microsoft’s Security Research and Defense blog:

A browse-and-get-owned attack vector exists. All that is needed is for a user to be lured to a malicious website. Triggering this vulnerability involves the use of a malicious XBAP (XAML Browser Application). Please not that while this attack vector matches one of the attack vectors for MS09-061, the underlying vulnerability is different.  Here, the affected process is the Windows Presentation Foundation (WPF) hosting process, PresentationHost.exe.

While the vulnerability is in an IE component, there is an attack vector for Firefox users as well. The reason is that .NET Framework 3.5 SP1 installs a "Windows Presentation Foundation" plug-in in Firefox, as shown below.

Good news is that, Microsoft has released a fix (MS09-054), which has been delivered through Windows Update. Firefox users, who haven’t installed this update, please open "Tools"-> "Add-ons" -> "Plugins", select "Windows Presentation Foundation", and click "Disable".

Installing a plugin with vulnerability without user consent into other browsers is a shame on Microsoft’s part, especially when they complain about Google’s Chrome Frame making IE less secure.

Related Posts that you may like:

Discussion

Comments for “Microsoft’s Plug-in puts Firefox Users at Risk”

  • SID
    Damn.. no wonder my Firefox is so slow. It also pretends to hang sometimes...!
  • I don't think this vulnerability slows down Firefox. I think it just makes your browser less-secure. Perhaps download some malicious stuff into your computer without your consent.
  • SID
    It definitely slowed down mine.. I just disabled the thing.. thanks for the info.. I've got lot of malicious stuff going on with my Firefox.. Damn..!!
  • Hmmm.. Maybe, unwanted plugins always bloat the browser. I don't like the idea behind Microsoft installing it without my consent. Not cool! Not one bit!
  • Hey guys, if i may go a bit off topic, have u noticed that the latest version of firefox using a lot of system resources. On one of my laptops; an aging one (running core2duo with a decent setup) It almost used up 497892K of memory, slowing the laptop to a standstill.
blog comments powered by Disqus

Welcome to TechBuzz

TechBuzz is a technology blog read by 3000+ readers every day. We regularly write about new trends in technology, useful computer application and new web services. If you are new here, please subscribe our feed or opt for email updates to get new articles to your inbox.

Free Daily Updates

You can get fresh daily articles delivered straight to your feed reader or email inbox. Please subscribe to our RSS feed or opt for our free newsletter

Recent Posts

Ixquick. Ixquick allows users to surf the web with complete privacy. It let’s users surf the world wide web safely without revealing any personally identifiable or private information to the websites being viewed.

Ixquick is a free service which provides complete anonymity to the user enabling the user to surf the internet anonymously and safely. They claim it to be world’s most private search engine.

Surf The Internet Anonymously With Ixquick!

Surf The Internet Anonymously With Ixquick!
January 28, 2010
By Meghan
Apple iPad Unveiled
January 28, 2010
By Meghan
Happy New Year!
January 1, 2010
By Meghan
WordPress Version 2.9 Is Out!
December 19, 2009
By Meghan
Lunascape 6 Orion: World’s Only Triple Engine Browser
December 13, 2009
By Meghan