Categorized | Security

News of AutoRun’s Death Has Been Greatly Exaggerated

Last week, I applied Microsoft Updates to one my Windows XP test machines and noted an optional update which restricts “AutoRun entries in the AutoPlay dialog to only CD and DVD drives”.

Update for Windows XP (KB971029)

You can see from the image above that the update is optional.

Yet, a Microsoft blog post about the update called it an “important, non-security update“.

Important updates are automatically applied by Microsoft Updates.

And so there was much rejoicing and AutoRun was declared dead.

But not so fast!

Larry Seltzer’s technically accurate (based on Microsoft’s statement) story about trimming AutoRun was followed up by another story with a correction from Microsoft.

“The functionality change to Autorun is, for the moment, marked as Optional for Windows XP. Users who have automatic updates set to install both Optional and Important updates have already begun to receive the update. We plan over the next few weeks to re-set the change to Important, allowing it to reach the remainder of the Automatic Update-using XP community.”

“Microsoft says that this was a miscommunication and not a mistake.”

And so AutoRun lives on, and even after Microsoft adjusts the update from optional to important for Windows XP, update KB971029 only limits non-optical media functionality.

So… to limit AutoRun, manually run Microsoft Updates. To completely kill AutoRun, click here and use the “fix it for me” option.

Regards,
Sean

On 15/02/11 At 01:56 PM

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago