<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>The Laws of Vulnerabilities</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/" />
    <link rel="self" type="application/atom+xml" href="http://laws.qualys.com/lawsblog/atom.xml" />
    <id>tag:laws.qualys.com,2008-02-21:/lawsblog//4</id>
    <updated>2010-03-11T16:03:01Z</updated>
    <subtitle>The Laws of Vulnerabilities</subtitle>
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type Commercial 4.23-en</generator>

<entry>
    <title>Update on Internet Explorer 0-day</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/03/update-on-internet-explorer-0-.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.251</id>

    <published>2010-03-11T15:52:36Z</published>
    <updated>2010-03-11T16:03:01Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="IE" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Microsoft" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="0day" label="0-day" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="internetexplorer" label="internet explorer" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="microsoft" label="microsoft" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[The exploit for the Internet Explorer 6 and 7 vulnerability announced yesterday (<a href="http://www.microsoft.com/technet/security/advisory/981374.mspx">KB981374</a>) is public now. Late yesterday, <a href="http://twitter.com/Trancer00t/status/10290064534">Moshe Ben Abu</a> published a <a href="http://www.rec-sec.com/2010/03/10/internet-explorer-iepeers-use-after-free-exploit/">Metasploit Module</a> for the exploit after tracking down the exploit to a webpage.
<br><br>   
> But Microsoft also released advisory KB981374 which describes a 0-day vulnerability
<br>
> reported to Microsoft only recently. At the moment only a limited number of targeted
<br>
> attacks have been reported. Internet Explorer 8 is not vulnerable, another good reason 
<br>
> to update to this latest version of IE. There are not a lot of details available on the 
<br>
> vulnerability, but for IE6/7 workarounds apply and are detailed in the advisory.]]>
        
    </content>
</entry>

<entry>
    <title>More on March&apos;s Patch Tuesday... </title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/03/more-on-marchs-patch-tuesday.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.250</id>

    <published>2010-03-10T01:25:51Z</published>
    <updated>2010-03-10T01:28:51Z</updated>

    <summary></summary>
    <author>
        <name>Qualys, Inc.</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Patch Tuesday" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[ <object height="340" width="560"><param name="movie" value="http://www.youtube.com/v/isRdugnT6tg&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed src="http://www.youtube.com/v/isRdugnT6tg&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="340" width="560"></object>]]>
        
    </content>
</entry>

<entry>
    <title>Patch Tuesday Bottomline - March 2010</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/03/patch-tuesday-bottomline---mar.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.249</id>

    <published>2010-03-09T18:39:53Z</published>
    <updated>2010-03-11T23:07:20Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="IE" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Microsoft" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Patch Tuesday" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="ie" label="IE" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="internetexplorer" label="Internet Explorer" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="macosx" label="Mac OS X" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="microsoft" label="Microsoft" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="moviemaker" label="Movie Maker" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="office" label="Office" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="patchtuesday" label="Patch Tuesday" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="producer" label="Producer" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="qualys" label="Qualys" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[ Contrary to what we expected last week, the Microsoft March Security announcements have a little surprise in it. 
<br /><br />
The standard bulletins cover Windows Movie Maker/Producer and Office:
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-016.mspx">MS10-016</a> - possible code execution in Windows Movie Maker - ranked important: an attacker can send a malicious file to the target. When the file gets opened, remote code execution is possible. The exploitability index is high, meaning that the file format vulnerability is relatively easy to exploit. Windows XP and Vista ship with vulnerable versions. While Windows 7 does not ship with a vulnerable version, a user could have downloaded and installed the  2.6 version, which is affected. The bulletin does not provide a patch for the also affected Windows Producer, a little used multimedia add-on to Powerpoint.
</li><li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-017.mspx">MS10-017</a> -  possible code execution in Microsoft Excel - ranked important as well. This bulletin covers 7 vulnerabilities, all of them file format based. All versions of Office are affected, including Mac Office 2004 and 2008. An attacker needs to trick the target to open a specially crafted Excel document, which will allow the attacker to take control of the target system. Exploitability is high for the majority of vulnerabilities listed, so we suggest to put this patch on a fast installation schedule. Attack vectors include also Excel viewer and SharePoint server. 
</li></ul>
But Microsoft also released advisory <a href="http://www.microsoft.com/technet/security/advisory/981374.mspx">KB981374</a> which describes a 0-day vulnerability reported to Microsoft only recently. At the moment only a limited number of targeted attacks have been reported. Internet Explorer 8 is not vulnerable, another good reason to update to this latest version of IE. There are not a lot of details available on the vulnerability, but for IE6/7 workarounds apply and are detailed in the advisory. 
<br /><br />
No major updates on advisory <a href="http://www.microsoft.com/technet/security/advisory/981169.mspx">KB981169</a>, also for Internet Explorer, which requires the target to press F1 to launch the attack and can best be avoided by user education.
<br /><br />
References:
<ul>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx">Microsoft March 2010 Bulletin</a></li><li><a href="http://www.qualys.com/research/alerts/view.php/2010-03-09">Qualys Security Alert</a><br /></li></ul>]]>
        
    </content>
</entry>

<entry>
    <title>Patch Tuesday - Preview for March 2010</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/03/patch-tuesday---preview-for-ma-1.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.244</id>

    <published>2010-03-04T19:25:39Z</published>
    <updated>2010-03-09T17:34:30Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="Microsoft" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Patch Tuesday" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="microsoftoffice" label="microsoft office" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="patchtuesday" label="patch tuesday" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="vista" label="vista" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="vulnerabilities" label="vulnerabilities" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="windows" label="windows" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="windows7" label="windows 7" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[After the massive February update Microsoft will only release 2 Bulletins next week. Both are rated as "important," a medium criticality rating for Microsoft. The first bulletin is for the Windows Operating System affecting the only desktop platforms XP, Vista and Windows 7.    The second Bulletin is for Microsoft Office and applies to all versions on  Windows (Office XP, 2003 and 2007) and Mac OS X (Office 2004 and 2008), plus SharePoint and the Excel Viewer.
<br><br>
The lower criticality ratings allow IT admins more time to address these March bulletins. It is likely that the Office vulnerabilities should be handled first, as file format vulnerabilities in general have been on the rise in the last year and end users frequently trust open office format files such as Excel due to their business oriented, serious nature.
<br><br>
Microsoft issued earlier this week an advisory KB981169 for a clever attack through Internet Explorer. It requires the end user to press F1 in a pop-up box, so the main defense is make your users aware of the existence of the flaw and instruct them to get in touch with IT should this happen.
<br><br>
Stay tuned for our detailed analysis on next Tuesday.
<br><br>
References:
<ul>
<li> <a href="http://www.microsoft.com/technet/security/Bulletin/MS10-mar.mspx">Microsoft Advanced Notification for March 2010</a>
<li><a href="http://www.microsoft.com/technet/security/advisory/981169.mspx">Vulnerability in VBScript Could Allow Remote Code Execution</a>
]]>
        
    </content>
</entry>

<entry>
    <title>CSA Top Threat Report Coming</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/02/csa-top-threat-report-coming.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.234</id>

    <published>2010-02-22T19:34:50Z</published>
    <updated>2010-02-22T19:42:33Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Threats &amp; Worms" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[For the last couple of months we have participated in the Cloud Security Alliance's project "Top Threats to Cloud Computing". A first version will be published at RSA 2010 at the <a href="http://www.cloudsecurityalliance.org/rsa2010.html">Cloud Security Alliance Summit</a> during <a href="http://www.rsaconference.com/2010/usa/">RSA 2010</a>. 
<br><br>
Please help us with this effort by completing the <a href="http://www.surveymonkey.com/s/VRPMBRM">Top Threats Survey</a>. The survey takes about 5 minutes to complete and will help us understand whether we are on the right track with the areas covered.
<br><Br>
The idea is to present summarized results of this survey at RSA. The project will continue to evolve after the conference as we incoporate your feedback.
<br><Br>
Come see the results at the Cloud Security Alliance Summit !]]>
        
    </content>
</entry>

<entry>
    <title>Adobe Patching Out-Of-band - Updated</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/02/adobe-patching-out-of-band.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.232</id>

    <published>2010-02-12T18:13:43Z</published>
    <updated>2010-02-16T21:48:15Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="Adobe" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[Updated: The Patch for Adobe Reader (<a href="http://www.adobe.com/support/security/bulletins/apsb10-07.html">9.3.1</a>) is now available - one of the flaws CVE-2010-0188 was found by <a href="http://blogs.technet.com/ecostrat/archive/2009/07/27/threat-complexity-requires-new-levels-of-collaboration.aspx">Microsoft's Research Team</a>.
<br><br>
Adobe announced a number of updates yesterday out of their normal 3-month cycle: <a href="http://www.adobe.com/support/security/bulletins/apsb10-06.html">APSB10-06</a> addresses a critical flaw in Adobe Flash and AIR. <a href="http://www.adobe.com/support/security/bulletins/apsb10-07.html">APSB10-07</a> is the announcement for an Adobe Reader and Acrobat update that will come out next Tuesday. It applicable to Windows, MAC OS X and Unix and critical as well. ]]>
        
    </content>
</entry>

<entry>
    <title>More on February&apos;s Patch Tuesday... </title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/02/more-on-februarys-patch-tuesda.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.230</id>

    <published>2010-02-10T02:37:03Z</published>
    <updated>2010-02-10T02:38:09Z</updated>

    <summary></summary>
    <author>
        <name>Qualys, Inc.</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Patch Tuesday" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[ <object height="340" width="560"><param name="movie" value="http://www.youtube.com/v/clw2joz1zY0&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed src="http://www.youtube.com/v/clw2joz1zY0&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="340" width="560"></object>]]>
        
    </content>
</entry>

<entry>
    <title>Patch Tuesday Bottomline - February 2010</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/02/patch-tuesday-bottomline---feb.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.229</id>

    <published>2010-02-09T18:36:10Z</published>
    <updated>2010-02-10T22:43:34Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="IE" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Microsoft" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Patch Tuesday" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="ie" label="IE" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="microsoftpatchtuesday" label="Microsoft Patch Tuesday" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="patchtuesday" label="Patch Tuesday" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[<a href="http://www.microsoft.com/technet/security/bulletin/ms10-feb.mspx">Microsoft's February 2010 Patch Tuesday</a> was slated to be the biggest release for Microsoft fixes in the last two years - 14 bulletins addressing 34 vulnerabilities. But the Google/CN Internet Explorer 0-day forced Microsoft to accelerate the testing of the planned IE bulletin and release it early, still in January. That leaves 13 bulletins covering 26 vulnerabilities for the February release, which constitutes one of the bigger patch Tuesdays.
<br /><br />
There are 5 critical vulnerabilities for the Windows Operating System family - the newer versions Windows 7 and Windows 2008 R2 are only affected by 3 of them. Rewrites of the TCP/IP stack and the URI handling in Windows 7 and 2008/R2 improved on the implementation of these core OS capabilities. 
<br /><br />
Overall highest on our list for patching are <a href="http://www.microsoft.com/technet/security/bulletin/ms10-006.mspx">MS10-006</a> SMB client and <a href="http://www.microsoft.com/technet/security/bulletin/ms10-013.mspx">MS10-013</a> DirectShow, which affect all versions of Windows and have a low exploitability index. Next are <a href="http://www.microsoft.com/technet/security/bulletin/ms10-007.mspx">MS10-007</a> Shell URL handling, which is critical for Windows 2000, XP and 2003 and <a href="http://www.microsoft.com/technet/security/bulletin/ms10-008.mspx">MS10-008</a>, an update to the ActiveX Killbit settings, applicable to all platforms.
<br /><br />
<a href="http://www.microsoft.com/technet/security/bulletin/ms10-012.mspx">MS10-012</a> is a bulletin for SMB that server administrators should focus on. It allows a malicious, unauthenticated  party to launch a remote denial of service attack. In addition remote authenticated clients can execute code using another flaw addressed in the bulletin. 
<br /><br />
<a href="http://www.microsoft.com/technet/security/bulletin/ms10-010.mspx">MS10-010</a> addresses an interesting vulnerability - it is in the hypervisor of Windows 2008. This virtualization vulnerability allows a  guest operating system to crash the host operating system, affecting all virtual machines running on the same physical host. Virtualization is increasingly used in corporate IT environments and in cloud computing initiatives and we see this class of vulnerability gaining importance. 
<br /><br />
Microsoft Office has 2 bulletins, both rated as important. While the newest version of Office for Windows, Office 2007, is not affected,  users of all other versions, including on MAC OS X should update as quickly as possible because file based vulnerabilities have been a favorite of attackers in the last year.<br /><br />References:<br /><ul><li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-feb.mspx">Microsoft Security Bulletin</a></li>
<li><a href="http://blogs.technet.com/srd/archive/2010/02/09/assessing-the-risk-of-the-february-security-bulletins.aspx">Technical insight from Microsoft</a></li>
<li><a href="http://isc.sans.org/diary.html?storyid=8197">SANS ranking for February 2010 patches</a></li>
</ul>


 
]]>
        
    </content>
</entry>

<entry>
    <title>IE 0-day Patched Out-Of-band</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/01/ie-0-day-patched.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.218</id>

    <published>2010-01-21T20:30:13Z</published>
    <updated>2010-01-27T23:30:33Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="IE" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Microsoft" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[Microsoft released today the patch for the critical Internet Explorer 0-day flaw that has been widely covered by us and the security community in general. <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">MS10-002</a> fixes a total of 8 vulnerabilities, including the 0-day which is identified as CVE-2010-0249 and is attributed to Meron Sellem from <a href="http://www.bugsec.com">BugSec</a>.
<br><br> 
In the MSRC <a href="http://blogs.technet.com/msrc/archive/2010/01/21/bulletin-ms10-002-released.aspx">blog post</a> announcing the release, Microsoft gives some insight on how they were able to turn around this patch in record time. Meron had reported the vulnerability in late August of 2009 and Microsoft had it confirmed in early September. By the time of public disclosure of the attacks against <a href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html">Google</a> and others, the fix was in essence ready and tested. It was slated for release in the February Patch bulletin. Microsoft had to decide whether an out-of-band release of the patch was warranted or whether to bundle it into the February release as originally planned. An out-of-band release causes additional work for IT administrators that are tasked with addressing operating system vulnerabilities and are have been  feeling the strain of keeping updated the growing number of software packages that attackers are increasingly targeting.
<br><br>
Nevertheless, given that exploits are available and that security researchers have shown that <a href="http://support.microsoft.com/default.aspx/kb/875352">DEP</a> as a defense can be circumvented, we recommend applying this update as soon as possible.
]]>
        
    </content>
</entry>

<entry>
    <title>IE 0-day Update</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/01/ie-0-day-update.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.217</id>

    <published>2010-01-20T00:08:54Z</published>
    <updated>2010-01-20T00:26:04Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="IE" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[Hi this is Richie again with some updates:
<br><br>
Internally we do not think of the IE 0-day that was released last week isn't something that is new or unique.  Every couple of months a new exploit for a critical vulnerability is discovered in the browser space and all major browsers see their share. Exploits of these types are commonly used in targeted attacks ("spear-phisihing") against corporations. What is new is that the affected organizations are coming forward with information on the attacks - a positive trend that we encourage and hope will continue.  
<br><br>
Technically, the attack was focused on the browser/OS combination IE6 and Windows XP, both close to 10 years old and near end of life. Microsoft has put a lot of work into increasing attack mitigation and surface hardening that reduces the risk of successful exploitation on newer versions of the Windows Operating System (Vista, Windows 2008, Windows 7).   In general users should upgrade to a modern OS/Browser combination, at minimum the browser should be updated to IE8 or another modern browser.  
<br><br>
As of now, the attacks are limited to a small target population and we have not seen widespread use of the exploit. We expect that to change in the coming days since details of the vulnerability have been made publicly available. Microsoft has released a <a href="http://blogs.technet.com/srd/archive/2010/01/18/additional-information-about-dep-and-the-internet-explorer-0day-vulnerability.aspx">Fix-It</a> which will turn on <a href="http://support.microsoft.com/kb/875352">DEP</a> for IE and help mitigate the attack. However there is active research going on to bypass the DEP measure and its effectiveness could be limited. 
<br><br>
Further Microsoft has <a href="http://blogs.technet.com/msrc/archive/2010/01/19/security-advisory-979352-going-out-of-band.aspx">indicated</a> that they will release an out-of-band patch for this issue soon. We will keep you updated with new developments as they arise. 
<br><br>
Thanks<br>
Richie Lai<br>
Director of Vulnerability Research, Qualys, Inc.<br>
<a href="http://twitter.com/rlaiqualys">http://twitter.com/rlaiqualys</a>]]>
        
    </content>
</entry>

<entry>
    <title>More Info on the IE 0-day</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/01/more-info-on-the-ie-0-day.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.216</id>

    <published>2010-01-15T00:30:45Z</published>
    <updated>2010-01-15T00:52:23Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="IE" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[Hi, my name is Richie Lai and I am the Director of Vulnerability Research here at Qualys.  Some of you might have seen me with Wolfgang during our monthly patch Tuesday webcasts.   We have been tracking some developments surrounding a 0-day in Internet explorer and I just wanted to give everyone information we've gathered.
<br><br>
Today Microsoft released an advisory for Internet Explorer versions 6 above and on all platforms up to Win7.   The current exploit that is in the wild results in code execution only on Internet Explorer 6 on XP.  The vulnerability exists in IE DOM parsing resulting in a dangling pointer potentially exploitable for remote code execution.  Even though the advisory lists all platforms as affected, there are a few mitigating factors.  
<br><br>
First, you are protected from this specific known exploit if Data Execute Protection (DEP) is enabled in the operating system.  While DEP has been proven to stop exploits like this, there are known ways to bypass DEP if you can get code running.  Which is where the second mitigating factor comes in, Address Space Layout Randomization (ASLR).  On platforms where both DEP and ASLR are enabled, exploitation is extremely difficult.  In the mean time, we suggest Windows XP users run Microsoft's "Fix-It" from the advisory which will enable DEP for IE 6 or 7 on XP.  Table outlining the current exploitability across all platforms and IE versions listed below.  As you can see, having the most updated browser will significantly reduce your exposure to this vulnerability at this time.  We will update you as we get more information regarding this development.
<br><br>
<style>
td { 
    text-color: black; 
    font-color: black;
    color: black;
    }

</style>

<table class=MsoNormalTable border=0 cellspacing=0 cellpadding=0
 style='border-collapse:collapse;mso-yfti-tbllook:1184;mso-padding-alt:0in 0in 0in 0in'>
 <tr style='mso-yfti-irow:0;mso-yfti-firstrow:yes;height:23.3pt'>
  <td width=65 valign=top style='width:49.1pt;border:solid black 1.0pt;
  padding:0in 5.4pt 0in 5.4pt;height:23.3pt'>
  <p class=MsoNormal><o:p>&nbsp;</o:p></p>
  </td>
  <td width=126 valign=top style='width:94.5pt;border:solid black 1.0pt;
  border-left:none;padding:0in 5.4pt 0in 5.4pt;height:23.3pt'>
  Windows 2000
  </td>
  <td width=120 valign=top style='width:1.25in;border:solid black 1.0pt;
  border-left:none;padding:0in 5.4pt 0in 5.4pt;height:23.3pt'>
  <p class=MsoNormal>Windows XP</p>
  </td>
  <td width=114 valign=top style='width:85.5pt;border:solid black 1.0pt;
  border-left:none;padding:0in 5.4pt 0in 5.4pt;height:23.3pt'>
  <p class=MsoNormal>Windows 2003</p>
  </td>
  <td width=108 valign=top style='width:81.0pt;border:solid black 1.0pt;
  border-left:none;padding:0in 5.4pt 0in 5.4pt;height:23.3pt'>
  <p class=MsoNormal>Windows Vista</p>
  </td>
  <td width=111 valign=top style='width:83.55pt;border:solid black 1.0pt;
  border-left:none;padding:0in 5.4pt 0in 5.4pt;height:23.3pt'>
  <p class=MsoNormal>Windows 2008</p>
  </td>
  <td width=107 valign=top style='width:80.6pt;border:solid black 1.0pt;
  border-left:none;padding:0in 5.4pt 0in 5.4pt;height:23.3pt'>
  <p class=MsoNormal>Windows 7</p>
  </td>
 </tr>
 <tr style='mso-yfti-irow:1;height:11.65pt'>
  <td width=65 valign=top style='width:49.1pt;border:solid black 1.0pt;
  border-top:none;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>IE 6</p>
  </td>
  <td width=126 valign=top style='width:94.5pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:#b22222;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>exploitable</p>
  </td>
  <td width=120 valign=top style='width:1.25in;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:#b22222;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>exploitable</p>
  </td>
  <td width=114 valign=top style='width:85.5pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:yellow;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>DEP protected</p>
  </td>
  <td width=108 valign=top style='width:81.0pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:Green;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>N/A</p>
  </td>
  <td width=111 valign=top style='width:83.55pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:Green;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>N/A</p>
  </td>
  <td width=107 valign=top style='width:80.6pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:Green;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>N/A</p>
  </td>
 </tr>
 <tr style='mso-yfti-irow:2;height:11.65pt'>
  <td width=65 valign=top style='width:49.1pt;border:solid black 1.0pt;
  border-top:none;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>IE 7</p>
  </td>
  <td width=126 valign=top style='width:94.5pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:Green;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>N/A</p>
  </td>
  <td width=120 valign=top style='width:1.25in;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:#b22222;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>exploitable</p>
  </td>
  <td width=114 valign=top style='width:85.5pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:yellow;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>DEP protected</p>
  </td>
  <td width=108 valign=top style='width:81.0pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:yellow;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>Protected by Protected Mode</p>
  </td>
  <td width=111 valign=top style='width:83.55pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:Green;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>N/A</p>
  </td>
  <td width=107 valign=top style='width:80.6pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:Green;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>N/A</p>
  </td>
 </tr>
 <tr style='mso-yfti-irow:3;mso-yfti-lastrow:yes;height:11.65pt'>
  <td width=65 valign=top style='width:49.1pt;border:solid black 1.0pt;
  border-top:none;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>IE 8</p>
  </td>
  <td width=126 valign=top style='width:94.5pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:Green;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  <p class=MsoNormal>N/A</p>
  </td>
  <td width=120 valign=top style='width:1.25in;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:yellow;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  DEP protected with XPSP3
  </td>
  <td width=114 valign=top style='width:85.5pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:yellow;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  DEP protected
  </td>
  <td width=108 valign=top style='width:81.0pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:Green;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  DEP and ASLR Protected  </td>
  <td width=111 valign=top style='width:83.55pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:Green;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  DEP and ASLR Protected
  </td>
  <td width=107 valign=top style='width:80.6pt;border-top:none;border-left:
  none;border-bottom:solid black 1.0pt;border-right:solid black 1.0pt;
  background:Green;padding:0in 5.4pt 0in 5.4pt;height:11.65pt'>
  DEP and ASLR Protected  </td>
 </tr>
</table>
<br><br>
Thanks<br>
Richie Lai<br>
Director of Vulnerability Research, Qualys, Inc.<br>
<a href="http://twitter.com/rlaiqualys">http://twitter.com/rlaiqualys</a>

]]>
        
    </content>
</entry>

<entry>
    <title>IE 0-day, Not Adobe Used in Data Breaches</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/01/ie-0-day-not-adobe-used-in-dat.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.215</id>

    <published>2010-01-14T22:20:20Z</published>
    <updated>2010-01-14T22:47:31Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="Adobe" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="IE" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[McAfee's CTO George Kurtz just <a href="http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/">published</a> some deeper insight into the attacks against Google. According to him a 0-day vulnerability in Internet Explorer was used. Microsoft has just issued an advisory <a href="http://www.microsoft.com/technet/security/advisory/979352.mspx">KB979352</a> acknowledging the vulnerability on all versions of Internet Explorer, except IE v5.
<br><br>
It looks as if the Adobe Reader 0-day was not directly involved, contrary to what we had <a href="http://laws.qualys.com/lawsblog/2010/01/updates-for-adobe-reader-on-pa.html">assumed</a> so far.
<br><br>
We will update this post when further information comes to our attention.
<br><br>
References:
<ul>
<li> <a href="http://www.wired.com/threatlevel/2010/01/hack-of-adob/">Wired post</a> by Kim Zetter
<li> <a href="http://news.cnet.com/8301-27080_3-10435232-245.html?tag=mncol;title">CNET News</a> by Elinor Mills
</ul>

 ]]>
        
    </content>
</entry>

<entry>
    <title>Adobe Patches 0-day Flaw Used In Stealth Attacks</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/01/updates-for-adobe-reader-on-pa.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.214</id>

    <published>2010-01-13T22:17:11Z</published>
    <updated>2010-01-13T22:46:03Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="Adobe" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Patch Tuesday" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Vulnerabilities" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[Yesterday Adobe Systems <a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">updated</a> its Reader product to fix a total of eight vulnerabilities. Out of the eight vulnerabilities, six allow remote code execution and are critical. One of the flaws addressed was CVE-2009-4324, the 0-day vulnerability which has had exploits in the wild since December 14 2009, roughly a month ago. This vulnerability is exploited by including malicious code in a PDF document and triggered by executing an embedded JavaScript program. The PDF can be delivered through e-mail or downloaded from a website, making it a fairly easy attack to execute. Interestingly enough it seems that this particular flaw was used in against Adobe itself as pointed out by <a href="http://news.cnet.com/8301-27080_3-10433744-245.html">Elinor Mills at CNET</a>.
<br><br>
Adobe has introduced two interesting security tools in the last two releases of the Reader product - one is an integrated update mechanism that will eventually default to automatic and silent updates. This mechanism is currently in beta and being tested with part of the <a href="http://blogs.adobe.com/asset/2010/01/a_few_words_on_the_january_201.html">installed base</a>. The second tool is a internal blacklist that allows hackers to disable specific JavaScript functions. Adobe recently provided <a href="http://kb2.adobe.com/cps/532/cpsid_53237.html">guidance</a> on how to mitigate the December 0-day by using this tool. Both tools are in their initial stages but look very promising.
<br><br>
The fixed versions are now Reader v9.3 and v8.2 . What is important for Adobe Reader v7 users to know is that v7 is <b>now out of support</b> (as of 12/28/2009 - see: http://www.adobe.com/support/products/enterprise/eol/eol_matrix.html#86) and is not being updated anymore with Security fixes. However, it is impacted by the December 0-day. IT administrators should take inventory of their v7 users and upgrade them to the current standard of v9.
<br><br>
References:
<ul>
<li><a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">Original Adobe Advisory</a>
<li><a href="http://www.qualys.com/research/alerts/view.php/2010-01-12-3">Qualys Advisory - QID 116768</a>
<li><a href="http://blogs.adobe.com/conversations/2010/01/adobe_investigates_corporate_n.html">Adobe Blog post on breach</a>
</ul>]]>
        
    </content>
</entry>

<entry>
    <title>More on January&apos;s Patch Tuesday... </title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/01/more-on-januarys-patch-tuesday.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.213</id>

    <published>2010-01-13T03:58:33Z</published>
    <updated>2010-01-13T04:14:13Z</updated>

    <summary></summary>
    <author>
        <name>Qualys, Inc.</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Patch Tuesday" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[ <object height="340" width="560"><param name="movie" value="http://www.youtube.com/v/q82o4y7CKmk&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed src="http://www.youtube.com/v/q82o4y7CKmk&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="340" width="560"></object><br /><br />
<a href="http://www.youtube.com/watch?v=q82o4y7CKmk&amp;hd=1">http://www.youtube.com/watch?v=q82o4y7CKmk</a>]]>
        
    </content>
</entry>

<entry>
    <title>Patch Tuesday Bottomline - January 2010</title>
    <link rel="alternate" type="text/html" href="http://laws.qualys.com/lawsblog/2010/01/patch-tuesday-bottomline---jan.html" />
    <id>tag:laws.qualys.com,2010:/lawsblog//4.212</id>

    <published>2010-01-12T22:08:02Z</published>
    <updated>2010-01-13T04:54:17Z</updated>

    <summary></summary>
    <author>
        <name>Wolfgang Kandek</name>
        <uri>http://www.qualys.com/</uri>
    </author>
    
        <category term="Adobe" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Microsoft" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Patch Tuesday" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://laws.qualys.com/lawsblog/">
        <![CDATA[ Microsoft starts 2010 slowly - a single bulletin containing one vulnerability in the embedded OpenType Font (EOT) engine. Due to the memory model in Windows 2000 the vulnerability is critical on that version of the Windows Operating System, all others receive a low severity rating. The flaw can be exploited through any OpenType enabled application such as Internet Explorer, PowerPoint, Word, etc  by viewing a webpage or a document. Users of Windows 2000 should upgrade as quickly as possible.
<br /><br /> 
There are 2 significant releases from other vendors today:
<br />
<ul>
<li>Oracle has released their quarterly <href a="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2010.html">Critical Patch Update today. It contains 25 fixes for 7 of their products, including application servers and database engine. The majority of the vulnerabilities are remotely exploitable without authentication and IT admins should be taking a close look at the exposure these products have in their networks. In general database engines should have no necessity to be connected to open networks,  but the application servers are very likely exposed.
</href></li><li>Adobe is also publishing their quarterly patch  - and it will address a vulnerability in Adobe Reader that was documented as being actively exploited in the wild since the week before Christmas. There are workarounds are available, the official recommendation is to blacklist the <a href="http://kb2.adobe.com/cps/532/cpsid_53237.html">JavaScript</a> function that is being exploited. Blacklisting is a capability introduced by Adobe in their last update to Adobe Reader v9 and v8 in October 2009 and might not be familiar to many IT admins yet. An alternative recommendation is to turn off JavaScript  completely in Adobe Reader - JavaScript has played a major role in the exploitation of Adobe Reader in 2009, so this a good preventive and defensive measure.  As this setting disables functionality potentially needed by users, IT admins need to evaluate their individual situations.
<br /><br />
This release is also introducing the new Adobe updater process, which will according to <a href="http://twitter.com/bradarkin/status/7641388444">Brad Arkin's tweet</a>  come preconfigured for automatic, silent updates à la Google Chrome
</li></ul>
Intevydis, a security research company in Russia has announced <a href="http://intevydis.blogspot.com/">last week</a> that they will publish server-based  0-day vulnerabilities for the next 3 weeks. The first two are live  and have POC code for Sun Directory Server 7.0 and Tivoli Directory Server 6.2. We are monitoring these releases and will keep you updated on further development.<br /><br />References:<br /><ul><li><a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx">Microsoft Security Bulletin</a></li><li><a href="http://www.qualys.com/research/alerts/view.php/2010-01-12-1">Qualys Security Advisory</a></li></ul><br />
]]>
        
    </content>
</entry>

</feed>
