Microsoft has officially responded to the discovery of a “blended threat,” the design of Safari that allows a malicious Web site to download and clutter the user’s download space with a myriad of unwanted files. This is the so-called “Carpet Bomb” effect.
While Microsoft’s Security Response Center is working on the problem with Apple and is not calling it a vulnerability of either Windows or Safari, they have issued a security advisory which provides guidance to Windows customers to restrict their use of Safari until an update is available from either Apple or Microsoft.
Microsoft’s official statement is as follows:
“Microsoft is investigating new public reports of a blended threat that allows remote code execution on all supported versions of Windows XP and Windows Vista when Apple’s Safari for Windows has been installed. Safari is not installed with Windows XP or Windows Vista by default: it must be installed independently or through the Apple Software Update application.
Microsoft issued Security Advisory (953818) to provide guidance to customers running Safari on the affected platforms to help them protect themselves. Microsoft is actively monitoring this situation to keep customers informed and will provide additional customer guidance as necessary. Security Advisory (953818) does not refer to a vulnerability in either Safari or Windows. Rather, it describes a blended threat in which files may be downloaded to a user’s machine without prompting, allowing them to be executed. This results from a combination of the default download location in Safari and how the Windows desktop handles executables. Safari is available as a stand-alone install or through the Apple Software Update application.
At the present time, Microsoft is unaware of any attacks attempting to exploit this blended threat. Upon completion of this investigation, Microsoft will take the appropriate measures to protect our customers. This may include providing a solution through…