Microsoft reports security problem with Apple's Safari

By Jacqueline Emigh | Published June 3, 2008, 12:41 PM

Microsoft, of all companies, has issued a security advisory warning users about a possible security exploit involving Apple's Safari for Windows browser.

In Microsoft Security Advisory 953818, posted last week, Microsoft does not pinpoint exactly how it learned of the security vulnerability. But users are told, "Microsoft is investigating new public reports of blended threat that allows remote execution on all supported versions of Windows XP and Windows Vista when Apple's Safari for Windows has been installed."

In the security glitch under investigation, "A combination of the default download location in Safari and how the Windows desktop handles executables creates a blended threat in which files may be downloaded to a user's machine without prompting, allowing them to be executed," Microsoft says.

"An attacker could trick users into visiting a specially crafted Web site that could download content to a user's machine and execute the content locally using the same permissions as the logged-on user."

Users who have changed the default location on the local drive for Safari downloads are not affected by the threat, according to Microsoft.

A blog post from Tim Rains of Microsoft Security Response Center last Friday contains what veterans will recognize as mostly boilerplate language, stating the company is unaware of any active exploits. Rains does add, however, that one way people find themselves with Safari for Windows on their systems is through the use of Apple Software Update, which is a component also installed in conjunction with iTunes and QuickTime.

As a suggested action, Microsoft recommends that users "restrict use of Safari as a Web browser until an appropriate update is available from Microsoft and/or Apple."

Comments

View comments by with a score of at least

Safari sucks even on a Mac so why would anyone willingly install it on a Windows machine for anything other than testing?

Score: 0

|

Uhhh yeah...it's not Apple's Safari that's the problem. It's that you're running it on Windblows! If you want a reliable computer that doesn't GET viruses or crash, buy a Mac! So worth the money.

Score: 0

|

http://www.maximumpc.com...to_home_base?page=0%2C1

In this maximumpc.com hosted article, MS recommends a user change the locations of where downloads are placed or to stop using the software all together until apple can update the software or MS patches windows from allowing this to happen. Personally, even as a mac user (and windows), it should be apple's responsibility to update the software to ask users if it is allowed to download any files from the internet. Kinda like when vista came out and people were having issues disconnecting their ipods from itunes using the eject icon and screwing up their ipod. Though people bashed vista early on for being a poorly polished OS (or something long those lines) it was apple's responsibility to provide an updated version of itunes that was more compatible with vista.

http://www.oreillynet.co...safari_carpet_bomb.html

This is a good article that a security researcher wrote about three vulnerabilities that he identified and reported to apple. One of them is this exact issue, which he calls "Safari Carpet Bombing".

Score: 0

|

simple solution DO NOT USE Safari!!!

Score: 0

|

Or don't use Windows... either way

What irks me is Microsoft won't say anything about exploits of their own programs... until they issue the patch for them as well and release both at the same time.

Score: 0

|

Everyone knows Microsoft sucks, they don't really need to announce it to us. This is why I use the big 3 platforms, b****ing rights. They all suck in their own ways, they all rock in their own ways. Show me a better gaming experience than that of a WINDOWS box and dont use consoles as an example...Show me a better video editing solution than that of a mac, or a safer, better, USEFUL and STABLE application variety than that of Linux. No one is immune from problems. Try getting an ATI AIW to work properly in SUSE linux if you dont believe me. Try doing more than media editing and media viewing/listening on a mac and you can see how BORING a mac can be. Yahoo messenger doesnt eve n have voice for a mac and Adium is the ONLY worth while instant messenger, featuring no audio. Skype has a client for all 3 which is nice.

Score: 0

|

Yea, use drugs instead...they would never try to log into your PC as an administrator.

That darn Microsoft.

Score: 0

|

Aaaaaand, nobody cares.

It's a terrible limited browser on both platforms.

Score: 0

|

Agreed.

Score: 0

|

Thats one nasty bug... but Microsoft should check their own foundation before they start making fun of the neighbors.

Score: 0

|

Right. They should have kept their mouths shut and let it slide.

A few exploits and reloads never hurt anyone, right?

Sorry, I didn't see the "Nah nah nah nah nah!" in their Advisory, did I miss where they were acting like they were 4 years old, or was that just you?

Score: 0

|

Microsoft recommends that users "restrict use of Safari as a Web browser until an appropriate update is available from Microsoft and/or Apple."

...or, since they obviously prefer Safari, how about they simply change their default download directory???

*shakes head*

That was lame, MSFT.

As for Vista being affected, it's only going to affect one of two types of users: Those with UAC disabled, or those who simply answer yes to every prompt made by UAC without question. (These are actually the same type of user: The Idiot user)

XP users are simply out of luck.

Score: 0

|

Those with UAC disabled != idiot user.

Some are, granted, but others who are conscious of where they go on the web, and what to download and what not to don't necessarily need nannying all the time.

Score: 0

|

Heh..

Of course....

But there are those who realize they are also human and can make mistakes.

Anyone who still thinks UAC is annoying hasn't used Vista for more than a day or two. It stops becoming an issue after the system is configured and only pops up on rare occasions after that.

Score: 0

|

So true. I've had my first UAC prompt in months, and that was installing the latest Creative X-Fi beta drivers recently.

Score: 0

|

Yes, disabling UAC is stupid.

Score: 0

|

Stupid people should not disable UAC.

problem solved.

Score: 0

|

I don't need Microsoft warning me about every little thing I do (regardless if they slack off after a while)...I have a grandmother to call when I need that. If I get herpes from that girl down the street its MY business.

Score: 0

|

People are stupid. :)

Score: 0

|

*laughs*

Yes it is, and we'd rather not hear about it if you do. ;)

Score: 0

|

If the people that disable UAC are stupid, and stupid people should not disable UAC, what is that?

UAC works, it's worked in Unix for many many years.

Disabling it in Windows is the dumbest idea ever.

If you are too damn lazy to do something as simple as typing in your password to perform an admin task; disconnect your keyboard, then your mouse, then your video, then your usb devices etc and place your CPU out at the street for the trash man.

Thanks.

Score: 0

|

I agree that it works and it works well.

Score: 0

|

I'm not going there..

Score: 0

|

To the radical fundamentalist zealots on both sides who are about to open fire: It's BOTH companies' faults. Get over it. Instead of bashing each other over the head like a bunch of toddlers fighting over a chalk line, how about trying to discuss the situation on its merits for once?

Don't like it? Don't use it. It's that easy.

Score: 0

|

how about trying to discuss the situation on its merits for once?

Try it yourself next time, mmmkay?

Don't like the comments? Don't read them.

It's really that easy. :)

Score: 0

|

This place's discussions are somewhat like a horrible car wreck; you see the mutilated and littered bodies and know you should look away, but you just can't.

I'll take the blame for being naïve enough to think people smart enough to work so deeply with technology could actually discuss things in a civilized, professional, mature manner. Hell, I've seen middle schoolers with behavioral issues deal with interpersonal conflict better than many threads in here. Yet, there's a pervasive attitude of "I'm right, you're wrong, now go to Hell" that even radical fundamentalist religious groups cannot begin to match. That's not a good thing.

Look above this threadlet; the requisite finger pointing & blaming and letter replacements & word games have already started. Another decent chance to talk about program security is turning into yet another turf war. So much talent and energy could be put to better use.

Me? I'm on vacation and this is entertaining. It's like watching monkeys throw feces at each other in a zoo. It really is that easy.

Score: 0

|

This place's discussions are somewhat like a horrible car wreck; you see the mutilated and littered bodies and know you should look away, but you just can't.

schadenfreude: a malicious satisfaction in the misfortunes of others.

I'll take the blame for being naïve enough to think people smart enough to work so deeply with technology could actually discuss things in a civilized, professional, mature manner.

For the most part, when presented with a mature and civilized discussion, we will respond in kind. Trolls abound, flamebait gets posted by both users *and* the editors, and we can have fun, release some steam, or ignore it. You'd be surprised based on the number of hits alone how many *do*, in fact, ignore it.

I've seen middle schoolers with behavioral issues deal with interpersonal conflict better than many threads in here.

Ah. you are assuming that everyone here has gone beyond middle school. That'd be your first mistake. ;)

Look above this threadlet; the requisite finger pointing & blaming and letter replacements & word games have already started.

See previous.

Me? I'm on vacation and this is entertaining. It's like watching monkeys throw feces at each other in a zoo. It really is that easy.

My life is a vacation. :)

Score: 0

|

Just more ammo for the "2-digit year 2000" phobes

Score: 0

|

always a fun read....
as far as im concerned one browser is not any better than the next. i dont see why a windows user would want to run mac product with it. or a mac user running explorer. whats the point other that personal taste. they all take you to the net, they all download crap.

the way mac hates ms you know they will go out of their way to not fix the problem. then they can do more ms bashing. mac will always play secound fiddle to ms and all the smoke and mirror routines they put on will never change that fact.

im glad they pointed it out. it shows that they do try to find the problems and fix them.

as for MS hiding problems id have to say no. in fact ive found them to be quite open about things. look at the s*** it caused them over vista. mac's whole selling campain is "bash windows". that makes me want to run right out and buy one....NOT
those who hate vista dont use vista. ive never had a use for a mac. but then im not into music the way some are.

Score: 0

|

Google Chrome 4: Yes, it's fast, but is it usable?

As Betanews readers have responded to our stories about Chrome's JavaScript superiority...Does that mean we'd actually use this browser? Well...

Video: Netflix on PlayStation 3

Netflix has come to the PlayStation 3 via Blu-ray and BD-Live.

Verizon Wireless launches new Android, Chocolate, and ruggedized phones

The lower-priced Eris joins the Droid, while the Chocolate gets a touchscreen and more music playback.

Early sales figures for Windows 7 nicely high, but do we know why?

Fans of triple-digit surges in figures quoted by Betanews will love this one, as it appears Microsoft rediscovered how to pull off a software launch.

Myka announces its latest Linux-based 'net top box'

Myka's ION brings Boxee, XMBC, and much more to HDTVs.

What hath Mac wrought? A remembrance after a quarter-century

The reason there's a Macintosh today is not because of some brilliant flash of engineering genius, but because Apple had the audacity to learn from its mistakes.

Early build of Moblin 2.1 improves connectivity, but not device support

The Linux Foundation's Atom-centric OS yesterday received a major overhaul with the project release of Moblin 2.1 for netbooks and nettops.

The iPhone's China syndrome: Sales of 5,000 and climbing

There's actually a country where Apple's device is not a godsend, where sales can be measured in the dozens.

New European counterpart to FCC will ensure 'a more neutral net'

Late Thursday night, the ruling telecom administrators of the EU's member nations signed away their final authority to a new entity overseen by the EC.

Sophos study suggests Windows 7 UAC's default setting is self-defeating

Without any anti-virus installed, a Sophos test showed, User Account Control was only capable of thwarting just one malware package out of ten samples chosen.

Indiscreet tweet trips awareness of Web SSL vulnerability

A group of high-level security engineers had been making progress on thwarting a low-level threat to the Web, until somebody blurted it all out on Twitter.