[x]Blackmoor Vituperative

Tuesday, 2009-06-09

Microsoft hacks Firefox, installs security hole

Filed under: Security,Software — bblackmoor @ 16:59

In a surprise move this year, Microsoft has decided to quietly install what amounts to a massive security vulnerability in Firefox without informing the user. […]

Microsoft pushed out its .NET Framework 3.5 Service Pack 1 update this February […] it installs the Microsoft .NET Framework Assistant extension for Firefox, silently, without informing the user. If you had Firefox on your computer when this update was installed, you may be subject to some dire consequences. […]

Yes, that’s right — the long-time, well known security hole present in Internet Explorer that consists of essentially letting Websites install dangerous, untrusted code on your computer willy-nilly has now been shoehorned into your MS Windows install of Firefox without your knowledge or permission.

Worse yet, Microsoft isn’t satisfied with just giving you vulnerabilities without your permission or even your knowledge. It has also gone out of its way to ensure that you’ll have a difficult time removing the vulnerability from your system if you should happen to become aware of it. The Uninstall button for this extension in Firefox has been deactivated.

(from Microsoft may be Firefox’s worst vulnerability, TechRepublic)

To find out how to remove this security vulnerability, see Uninstalling the Clickonce Support for Firefox.