Microsoft .NET Update installs Firefox Add-on Without Permission

If you are completely up-to-date with Windows patches via Windows Update and you run Firefox you may be in for a surprise. In Firefox go to Tools->Add-ons and scroll down the list of add-ons you have installed. You’ll likely find an entry for “Microsoft .Net Framework 1.0″. If you do, you won’t remember deciding to install it as Microsoft did it automatically without your knowledge or approval.

The install happened as part of a Microsoft .Net Framework service pack update back in February. The problem is that such an add-on makes it easier for software to be installed on your system with just a single mouse click. According to Annoynaces.org:

This update adds to Firefox one of the most dangerous vulnerabilities present in all versions of Internet Explorer: the ability for websites to easily and quietly install software on your PC. Since this design flaw is one of the reasons you may’ve originally chosen to abandon IE in favor of a safer browser like Firefox, you may wish to remove this extension with all due haste.

It gets worse than that, however, as Microsoft decided to disable the uninstall option for the add-on. So you can’t remove it without going through a complicated series of steps also listed on Annoyances.org. You can choose to disable it though, which is the next best option.

According to Microsoft they added support for what they call “ClickOnce” due to user demand. The reason for the lack of uninstall option is because Microsoft wanted to support all users on a machine so had to do it at the machine level. They have issued a fix for this, but it requires uninstalling the .Net Framework and then reinstalling an updated version. You can read all about that on Microsoft’s Brad Abrams blog.