Friday December 5, 2008 7:44 PM AEST
Latest Comments
"Excellent info. If you use Gumtree Australia you will see many obvious scam posts in all ..."
by Marian Imrie | Dec 5, 2008 4:45 PM
 
"Very nice and useful information. UT4B4. Tape4backup.com"
by Lto-4 Tape | Dec 4, 2008 9:23 PM
 
"Interesting that you do not bother to list the one AV that has consistently passed the VB100. ..."
by Ben | Dec 4, 2008 6:00 PM
 
"I like this"
by nanwin | Dec 3, 2008 3:05 PM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM

Attackers exploit recent Microsoft fix

  • Email a Friend
  • Print Page
Attackers exploit recent Microsoft fix
By Sue Marquette
Apr 16, 2008 10:33 AM
Tags: Attackers | exploit | recent | Microsoft | fix
Craig Schmugar, threat researcher at McAfee, reported that the first exploit was discovered on Friday, three days after the issue was patched by bulletin MS08-021.

On Monday, hackers publicly posted a basic exploit toolkit, which signals that the criminal underground may soon develop a more sophisticated and widespread way to take advantage of the bug.

"One method the bad guys use is to take the patch and reverse engineer it," Schmugar told SCMagazineUS.com on Tuesday. "They look at the files on the computer prior to installing the patch and then after, and try to compare the two and see how they can take advantage of the change."

The exploit – which can permit remote code execution if a user opens a specially crafted EMF or WMF image file – does not affect customers who have installed the updates detailed in MS08-021, said Bill Sisk, security response communications manager for Microsoft.

"By default, Microsoft Windows XP, Windows Vista, Windows  Server 2003, and Windows Server 2008 customers will have this update applied automatically through Automatic Updates," Sisk said.

Microsoft encourages all customers to apply its most recent security updates to help ensure that their computers are protected from attempted criminal attacks.

Schmugar said that GDI has had vulnerability issues in the past. The fact that Microsoft credited three researchers with discovering the flaw suggests that multiple people were looking for potential problems and more problems could be on the way.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Patch Management Whitepapers