Microsoft acknowledges a bug in Windows’ Animated Cursor, a component that lets developers show animation at the mouse pointers location. The SANS Institute, in fact, said it had received reports of in-the-wild exploits using files renamed to.ani. The next scheduled update cycle for the Redmond, Wash. developer is April 10. Microsoft said it would patch the bug in a security update, but would not commit to a when. The MRSC downplayed the threat by claiming only “very limited” attacks were in progress.”]
Source: https://www.csoonline.com/article/2121217/critical-zero-day-microsoft-windows-flaw-confirmed.html