Recently in Security Category

A week has passed since Microsoft published security advisory KB2269637 that details the technology underlying the DLL hijacking vulnerabilities. Since then security researchers have looked at Windows applications from 3rd parties and from Microsoft itself and have identified many vulnerable programs Last week HD Moore from Rapid7 published an even better version of his DLL Hijacking finding tool that is in use by many of the researchers. Microsoft gave a very illustrative example on how a vulnerable application could be attacked on their SRD blog just this week.

We recommend installing the Microsoft Hotfix downloadable from KB2264107 and creating the CWDIllegalInDllSearch registry key, which instructs Windows to exclude the current working directory from the DLL loadpath when an application is started from network or WebDAV locations. In addition IT admins should keep an eye on the excellent list on vulnerable applications and their fix status that is being maintained by Secunia.

In Qualysguard we have introduced 2 new QIDs that are designed to help the IT admin to manage the installation of this Hotfix:
  • QID 118423 - Microsoft Windows DLL Search Order Design Error Vulnerability (KB2269637)
    This detection indicates that the machine does not have the Hotfix installed
  • QID 90634 - Hotfix KB2264107 (DLL hijacking) is Installed
    This detection indicates that the machine has the Hotfix installed and will contain the setting for registry key CWDIllegalInDllSearch in the result section
Microsoft has just published security advisory KB2269637 that provides IT admins with the information and tools to deal with DLL hijacking. DLL hijacking attacks are targeted at Windows applications (3rd part and Microsoft) that have not followed recommended security practices and can be tricked to load DLLs from locations that are owned by the attacker. The attacker provided DLL is then used to take control of the target machine.

According to security research by Taeho Kwon and Zhendong Su from UC Davis, ACROS Security and HD Moore from Rapid7, it is straightforward to find applications that do not follow these best practices. Two weeks iTunes was patched for an occurrence of "binary planting" and Simon Raner of ACROS Security was credited.

The underlying idea of the attack is older (some discussion of the underlying issue is here from 2000) and not limited to Windows. Over time fixes and workarounds have been implemented, but a new attack vector using network shares and WebDAV increases the usability of the attack. With the available documentation and tools it is now easy to find vulnerable applications and craft exploits.

We recommend installing the hotfix in KB2264107 and setting the registry to not allow loading of binaries via network shares and WebDAV (setting 2) as soon as possible.

References:
A busy week - in addition to Microsoft August's Patch Tuesday which delivers a record setting 15 bulletins covering 35 vulnerabilities, Adobe has just released a Flash update and will be releasing a patch for a Adobe Reader 0-day vulnerability published a few weeks ago at Black Hat security conference.To help with this challenging patch workload, we have ranked the Microsoft bulletins into three distinct groups of updates, which can be addressed on different schedules.

IT admins should first tackle the updates that represent the biggest attack potential: end-users and internet browsing are at the subject of six bulletins, all of them of critical severity and four of them with an exploitability rating of "1", indicating that working exploits are expected within 30 days. MS10-053 has six direct fixes for Internet Explorer, while the ZDI submitted MS10-055 and MS10-052 address issues in media-plugins: MS10-055 for the Cinepak codec and MS10-052 for the MP3 file format. MS10-060 patches a critical .NET framework issue that can be exploited through web browsing/Silverlight and MS10-051 addresses a vulnerability in the Internet Explorer MSXML ActiveX component. MS10-049 deals with a client side vulnerability of the HTTPS protocol that can be triggered by a malicious HTTPS site. This and the previous MSXML ActiveX component are the bulletins in the group that are rated "2" on the exploitability scale (= harder to exploit). All of these updates should be applied as soon as possible.

A second group of updates has its focus on file format vulnerabilities. The most critical is MS10-056, a vulnerability in the RTF format in Microsoft Word 2007 and older. An attacker can craft a malicious file that triggers a remote code execution when opened by Word on the target computer. Users of Outlook 2007 installations need to pay special attention, since the preview pane in Outlook is configured by default to use Word to render the RTF format. This makes Outlook 2007 susceptible to an attack that does not even require the opening of the e-mail. Apply this update as quickly as possible. MS10-057 and MS10-050 provide fixes for Excel 2003 and earlier and Windows Movie Maker (a default component in Windows XP) file format vulnerabilities. Both have an exploitability rating of "1" and should be addressed as soon as possible.

MS10-058 deals with an interesting vulnerability. It is a located in the new TCP/IP stack for IPv6 under Vista, Windows 7 and 2008R2. While we believe that currently very few publicly facing network infrastructures have IPv6 enabled, this bulletin is important for them, because it is remotely attackable and few mitigations exist. It is a reminder that new OS components and applications are apt to introduce new attack vectors into networks. MS10-054 is a vulnerability in the SMB protocol; it requires read access to a share as well as attacker-controlled data on the target machine. The exploit here will most likely manifest itself as a local escalation of privilege attack.

The remainder of the August updates all address local flaws of the Windows Operating system family and are rated important as the attacker needs to be present on the target system to make use of them. MS10-047 is a Windows Kernel flaw, MS10-048 a flaw in the win32k.sys driver and MS10-059 fixes a problem in the tracing component of Windows.

Last week Microsoft released a bulletin for the 0-day flaw using the LNK filetype. If you have not done so yet, apply MS10-046 together with the first group of patches as desktop systems are at the highest risk of attack using the LNK vulnerability.

References:

Adobe announced that they will publish an out-of-band update APSB10-17 for a 0-day vulnerability published during Charlie Miller's BlackHat talk.

Charlie Miller's BlackHat paper is a result of a collaboration with Prof. Dawn Song from UC Berkeley and a continuation of his fuzzing efforts first revealed at the CanSecWest conference. At the time the tools he used were CrashWrangler and !exploitable, but it seems that BitBlaze, the tool from Prof. Song's research group provides much better insight into exploitable application crashes.
This August is bringing a record setting number of updates from Microsoft. In addition to last week's LNK update, there will be another 14 bulletins addressing 34 vulnerabilities, that IT admins will have to take care of in the weeks after Patch Tuesday. Including the LNK update,9 bulletins have a rating of critical and affect all version of the Windows OS, Internet Explorer, Silverlight and Microsoft Office.

Windows 7 and 2008 R2 have a smaller number of critical vulnerabilities than Windows XP and 2003 in function of their improved security architecture, but are still affected by 2 critical vulnerabilities each.

Internet Explorer, Office and Silverlight updates apply across the board on all Windows versions. They are a examples of the this increasingly used type of flaw, where attackers and malware go through the installed applications rather than through the core operating system.

Windows XP SP2 users do not have any patches supplied to them, even though the 5 critical vulnerabilities for XP SP3 most likely apply to their discontinued version of the OS as well. Windows XP SP2 users should upgrade to SP3 as quickly as possible.
Microsoft released an update today that addresses the LNK vulnerability. The update is rated as critical and applies to all currently supported Windows Operating systems.

We recommend applying the update as quickly as possible. Attacks using this 0-day vulnerability have been increasing.

The recently discontinued Windows 2000 and Windows XP SP2 are not covered by the patch. Users of these Windows 2000 and XP SP2 need to work on an upgrade strategy for these operating systems, as over time without patch support they will become increasingly susceptible to attacks from malware
Update
Businessweek has an article about the SCADA connection of this flaw, Siemens has issued an advisory and update for the software components that are being attacked by some strains of the malware.

Original
Just three days after July's Patch Tuesday, Microsoft issued an advisory for an issue affecting all current Windows Operating Systems. The flaw is located in Windows Shell and can be used to execute arbitrary code on vulnerable systems. According to the advisory, Microsoft is aware of targeted attacks in the wild exploiting the issue. Brian Krebs reports that Russian AV company VirusBlokAda detected the attack while analyzing a new malware sample.

The advisory lists workarounds that can be implemented by editing the registry. They change the way certain icons are visualized, so there is a visible impact on the desktop of the user.

The advisory does not list Windows XP SP2, or Windows 2000 for that matter, as being affected, because Microsoft just ended support for both Operating Systems last Tuesday. However we assume the attack works against both of them and attackers will surely take advantage of this security hole. We recommend upgrading your existing Windows XP SP2 installations to SP3 as soon as possible to be able to install the security update for this issue once Microsoft publishes it. Windows 2000 users face a bigger hurdle and they need to upgrade to an entirely new Operating System.

Microsoft's July update is small - four bulletins in total, two of them addressing security flaws in Windows and two for Microsoft Office. Both Windows bulletins have a maximum rating of critical and both address previously disclosed vulnerabilities. The first one is for Windows XP and 2003 and fixes the Windows Help and Support Center vulnerability published by Tavis Ormandy in a much discussed full disclosure move. Microsoft showed some impressive turnaround time on that patch. The second bulletin fixes a problem in the AERO display driver component for Windows 7 and Windows Server 2008 R2, which was disclosed publicly earlier in May.

The two remaining bulletins, one ranked critical and one important, are for Microsoft Office and all versions but the new Office 2010 are affected, including Office XP, Office 2003 and Office 2007.

July also marks the end of support for two important Microsoft Operating Systems, Windows XP SP2 and Windows 2000. Windows XP SP2 users are advised to upgrade to SP3, which will be supported throughout 2014. Windows 2000 users need to upgrade to a different version of the operating system altogether, as the entire Windows 2000 line is discontinued.

References:

Update: Original:

Earlier today Tavis Ormandy released an advisory disclosing a new vulnerability in Windows XP and Windows 2003. The vulnerability is in the Windows Help and Support Center component and is accessed through the protocol handler "hcp://". It can be triggered through all major browsers, but as Tavis points out it is easier to exploit under IE7. Tavis provides sample exploit code for both IE8 and IE7 in the advsiory.

As a work-around for the vulnerability, it is possible to de-register the HCP protocol on the target machine:

  1. From the Start Menu, select Run
  2. Type regedit then click OK (The registry editor program launches)
  3. Expand HKEY_CLASSES_ROOT and highlight the HCP key
  4. Right mouse click on the HCP key, and select Delete
This workaround will disable all local, even legitimate help links that use hcp://. For example links in the Control Panel may no longer function. For more details on the workaround consult MS03-044, which lists the above instructions for an older vulnerability in the Help system.

Tavis' decision to use full disclosure for this vulnerability will certainly revive the discussions around full vs. responsible disclosure. Tavis provides some comments regarding that discussion and includes references to articles by Bruce Schneier exploring the matter.

We are working on testing the exploit and will update this post when new developments occur.

Updates:
Microsoft released its June 2010 advance notification for next week's Patch Tuesday. We will see 10 security bulletins addressing a total of 34 vulnerabilities. Of the 10 bulletins, 3 are categorized as critical, allowing an attacker to take full control of the targeted machine, while the remaining 7 are ranked as important. The critical vulnerabilities affect all Windows OS versions (including Windows 7) and Internet Explorer, the important ones cover Windows and Office.

The June release is a large update and will keep system administrators busy, even if they have migrated to Windows 7 already (the end of life date for Windows XP SP2 is coming closer and Windows 7 is certainly one of the options to migrate to...)

Microsoft will also address 2 currently open vulnerabilities: in SharePoint (detailed in advisory KB983438) and an information leakage in Internet Explorer, explained in advisory KB980088

Some of the patches, including one of the critical ones require a machine reboot after installation.

References:
Microsoft's release for May 2010 contains 2 Bulletins (MS10-030 and MS10-031) fixing 2 vulnerabilities, one of its low impact releases. MS10-031 is for Microsoft Office and addresses a remote code execution vulnerability present in all versions, Office XP, 2003 and 2007. Its exploitability index is 2, so exploit code within the next 30 days is unlikely. Microsoft's blog post at the SRD goes into further detail on the difficulties in writing a working exploit. While the bulletin only carries a severity of "important", we consider it to be the more urgent of today's release.

The second bulletin MS10-030 fixes a vulnerability in Windows Outlook Express and Windows Mail, both mail clients for the POP/IMAP protocols. The vulnerability allows remote code execution and is classified as "critical". Successful exploitation however is unlikely (exploitability index = 2) as it requires extensive user involvement including setting up an e-mail account on a malicious server. We don't see Outlook Express/Windows Mail being used in the enterprise but smaller businesses could be affected.

Microsoft did not address the recent SharePoint vulnerability (KB983438). We recommend looking into the advisory and implementing the suggested work-around which restricts the access to the Help functionality in SharePoint.
Oracle/Sun today released an update to Java that addresses the 0-day from last week.

Ryan Naraine at Threatpost has a good writeup and screenshots showing the blocking of the testurl that Tavis Ormandy Included in his initial disclosure.

We recommend immediate installation as the exploit has apparently been sighted already on a number of websites
Microsoft's patch release for April contains 11 bulletins covering 25 vulnerabilities. The bulletins address a wide array of operating systems and software packages, IT administrators with a good inventory of their installed base will have an easier time evaluating which machines need patches.

Microsoft patches 2 open 0-day vulnerabilities - MS10-020 for the SMBv2 Denial of Service vulnerability, only present on Windows 7 and Windows Server 2008 (KB977544) and MS10-022 for the F1 attack through Internet Explorer (KB981169). MS10-020 fixes other SMB vulnerabilities as well and is a critical update for all platforms.

The most critical bulletins this month are MS10-026, MS10-027 and MS10-019. MS10-026 addresses a DirectShow vulnerability that can be exploited through visualizing a media file which can lead to remote code execution. MS10-027 is a Windows Media Player Active X control vulnerability which can lead to similar results. Both are relatively easy to exploit and have a low exploitability index, however Windows 7 users are not affected by either of the vulnerabilities. MS10-019 addresses a flaw in the Windows Authenticode algorithm involved during the installation process of new software. The flaw allows for a downgrade from the current v2 Authenticode algorithm to the deprecated v1 algorithm. If an attacker follows this downgrade with an attack on v1 (a sophisticated multi-stage attack), he could pass off malicious install packages as legitimately signed by major manufacturers. This vulnerability has a exploit rating of difficult, meaning that even advanced attackers will take a while to come up with the necessary exploit code - still we recommend patching this during the normal cycle for all machines.

MS10-025 is a critical Windows Media Services vulnerability but only affects Windows 2000. Windows 2000 Server will have its extended Support retired in mid-July of this year and will then cease to receive security updates. Organizations that still use Windows 2000 need to evaluate a migration strategy.

The remaining bulletins are ranked as important and moderate - MS10-028 is a file format attack against Visio, which can result in remote code execution. MS10-023 is a similar attack against Microsoft Publisher. As these software packages are not widely installed a good inventory will be helpful in evaluating the exposure. MS10-021 is an interesting side effect created by registry linking. MS10-024 is a Denial of Service vulnerability in the SMTP server of Windows 2003-64bit only and MS10-029 an IPv6/IPv4 packet envelope vulnerability that can lead to information disclosure.

This is a big release for Microsoft, addressing a wide selection of software. IT administrators probably will not have all of the included software packages and configurations installed in their environment and therefore will need to install only a subset of the 11 bulletins.

In addition Adobe released their quarterly patches for Adobe Reader and Acrobat on Windows, Mac OS X and Unix. The update is critical and fixes multiple 15 vulnerabilities with a maximum exposure of "remote code execution".

References:
Today Microsoft released their advance notification for next week's Patch Tuesday. There will be 11 security bulletins (5 critical) affecting a range of Windows operating system components as well as Microsoft Office and Microsoft Exchange. This is a fairly large update and will keep system administrators busy.

Of particular interest is that Microsoft will fix 2 open 0-day vulnerabilities - the F1 attack through the Internet Explorer KB981169 and the SMBv2 Denial of Service vulnerability, only present on Windows 7 and Windows Server 2008 KB977544.

The 5 critical bulletins affect Windows 2000, XP, Vista, 2003, 2008 and Windows 7. An attacker can use these vulnerabilities to remotely execute code on the victim's machine and they should be addressed as quickly as possible.

An additional 5 security bulletins are rated as important and apply to Microsoft Office, Microsoft Exchange and Windows. If left un-patched, an attacker could execute code, cause a denial of service or obtain elevated privileges on the victim's machine. The remaining security bulletin is rated as Important.

Most of the patches require a machine reboot after installation.

Similar to past Patch Tuesdays, Windows 7 has less critical updates to install than the older operating systems versions, an indication that the newer version of Windows are more robust and secure out of the box.

In addition to the Microsoft patches, administrators will also have to pay attention to the security fixes coming out from Adobe for the Reader and Acrobat products. The Adobe update is rated as critical and a successful exploit will allow the attacker to take control of the target machine.
Today Microsoft released MS10-018, a critical bulletin with 10 patches affecting all versions of Internet Explorer. The release includes the patch for the one of the current 0-day exploits against IE6 and IE7, the "iepeers" (KB981374 and CVE-2010-0806) vulnerability. The original schedule for the bulletin was April 13th, during the normal April Patch Tuesday, but it was anticipated because Microsoft has detected an increase in exploits for that 0-day vulnerability..

All users of Internet Explorer 6 and 7 should patch immediately, as the exploit for these versions in known and becoming more popular.

Users of Internet Explorer 8 are not affected by the exploit, but the bulletin contains 2 critical vulnerabilities for this version, so we can expect exploit code for them soon. IT Admins will have to decide whether they can take the risk of patching IE8 only during next patch Tuesday - 2 weeks out, or whether to patch sooner and incur the cost of having 2 separate patch days.

The other open 0-day, the F1 flaw in IE has not been fixed yet, and last week's PWN2OWN IE8 flaw is still under investigation by the security team at Microsoft, so we will continue to see updates in the browser area.
Microsoft will release MS10-018 a patch for the critical Internet Explorer 0-day vulnerability KB981374 out of band tomorrow, on March 30th. Microsoft's decision to accelerate the release rather than waiting until next Patch Tuesday on April 13th is an indication that attacks against the "iepeers" vulnerability are on the rise.

Similar to what happened with the last IE 0-day patch MS10-002, Microsoft is including fixes for 9 other vulnerabilities, so the patch is critical for ALL versions of IE

If you are still using IE6 or IE7, patch immediately. But even if you are on IE8 you should patch as quickly as possible, as attackers will start reverse engineering the flaws addressed and preparing corresponding exploits within the week.

Kudos to Microsoft for their quick turn-around on this vulnerability.
The exploit for the Internet Explorer 6 and 7 vulnerability announced yesterday (KB981374) is public now. Late yesterday, Moshe Ben Abu published a Metasploit Module for the exploit after tracking down the exploit to a webpage.

> But Microsoft also released advisory KB981374 which describes a 0-day vulnerability
> reported to Microsoft only recently. At the moment only a limited number of targeted
> attacks have been reported. Internet Explorer 8 is not vulnerable, another good reason
> to update to this latest version of IE. There are not a lot of details available on the
> vulnerability, but for IE6/7 workarounds apply and are detailed in the advisory.
Contrary to what we expected last week, the Microsoft March Security announcements have a little surprise in it.

The standard bulletins cover Windows Movie Maker/Producer and Office:
  • MS10-016 - possible code execution in Windows Movie Maker - ranked important: an attacker can send a malicious file to the target. When the file gets opened, remote code execution is possible. The exploitability index is high, meaning that the file format vulnerability is relatively easy to exploit. Windows XP and Vista ship with vulnerable versions. While Windows 7 does not ship with a vulnerable version, a user could have downloaded and installed the 2.6 version, which is affected. The bulletin does not provide a patch for the also affected Windows Producer, a little used multimedia add-on to Powerpoint.
  • MS10-017 - possible code execution in Microsoft Excel - ranked important as well. This bulletin covers 7 vulnerabilities, all of them file format based. All versions of Office are affected, including Mac Office 2004 and 2008. An attacker needs to trick the target to open a specially crafted Excel document, which will allow the attacker to take control of the target system. Exploitability is high for the majority of vulnerabilities listed, so we suggest to put this patch on a fast installation schedule. Attack vectors include also Excel viewer and SharePoint server.
But Microsoft also released advisory KB981374 which describes a 0-day vulnerability reported to Microsoft only recently. At the moment only a limited number of targeted attacks have been reported. Internet Explorer 8 is not vulnerable, another good reason to update to this latest version of IE. There are not a lot of details available on the vulnerability, but for IE6/7 workarounds apply and are detailed in the advisory.

No major updates on advisory KB981169, also for Internet Explorer, which requires the target to press F1 to launch the attack and can best be avoided by user education.

References:
After the massive February update Microsoft will only release 2 Bulletins next week. Both are rated as "important," a medium criticality rating for Microsoft. The first bulletin is for the Windows Operating System affecting the only desktop platforms XP, Vista and Windows 7. The second Bulletin is for Microsoft Office and applies to all versions on Windows (Office XP, 2003 and 2007) and Mac OS X (Office 2004 and 2008), plus SharePoint and the Excel Viewer.

The lower criticality ratings allow IT admins more time to address these March bulletins. It is likely that the Office vulnerabilities should be handled first, as file format vulnerabilities in general have been on the rise in the last year and end users frequently trust open office format files such as Excel due to their business oriented, serious nature.

Microsoft issued earlier this week an advisory KB981169 for a clever attack through Internet Explorer. It requires the end user to press F1 in a pop-up box, so the main defense is make your users aware of the existence of the flaw and instruct them to get in touch with IT should this happen.

Stay tuned for our detailed analysis on next Tuesday.

References:
For the last couple of months we have participated in the Cloud Security Alliance's project "Top Threats to Cloud Computing". A first version will be published at RSA 2010 at the Cloud Security Alliance Summit during RSA 2010.

Please help us with this effort by completing the Top Threats Survey. The survey takes about 5 minutes to complete and will help us understand whether we are on the right track with the areas covered.

The idea is to present summarized results of this survey at RSA. The project will continue to evolve after the conference as we incoporate your feedback.

Come see the results at the Cloud Security Alliance Summit !
Updated: The Patch for Adobe Reader (9.3.1) is now available - one of the flaws CVE-2010-0188 was found by Microsoft's Research Team.

Adobe announced a number of updates yesterday out of their normal 3-month cycle: APSB10-06 addresses a critical flaw in Adobe Flash and AIR. APSB10-07 is the announcement for an Adobe Reader and Acrobat update that will come out next Tuesday. It applicable to Windows, MAC OS X and Unix and critical as well.
Microsoft's February 2010 Patch Tuesday was slated to be the biggest release for Microsoft fixes in the last two years - 14 bulletins addressing 34 vulnerabilities. But the Google/CN Internet Explorer 0-day forced Microsoft to accelerate the testing of the planned IE bulletin and release it early, still in January. That leaves 13 bulletins covering 26 vulnerabilities for the February release, which constitutes one of the bigger patch Tuesdays.

There are 5 critical vulnerabilities for the Windows Operating System family - the newer versions Windows 7 and Windows 2008 R2 are only affected by 3 of them. Rewrites of the TCP/IP stack and the URI handling in Windows 7 and 2008/R2 improved on the implementation of these core OS capabilities.

Overall highest on our list for patching are MS10-006 SMB client and MS10-013 DirectShow, which affect all versions of Windows and have a low exploitability index. Next are MS10-007 Shell URL handling, which is critical for Windows 2000, XP and 2003 and MS10-008, an update to the ActiveX Killbit settings, applicable to all platforms.

MS10-012 is a bulletin for SMB that server administrators should focus on. It allows a malicious, unauthenticated party to launch a remote denial of service attack. In addition remote authenticated clients can execute code using another flaw addressed in the bulletin.

MS10-010 addresses an interesting vulnerability - it is in the hypervisor of Windows 2008. This virtualization vulnerability allows a guest operating system to crash the host operating system, affecting all virtual machines running on the same physical host. Virtualization is increasingly used in corporate IT environments and in cloud computing initiatives and we see this class of vulnerability gaining importance.

Microsoft Office has 2 bulletins, both rated as important. While the newest version of Office for Windows, Office 2007, is not affected, users of all other versions, including on MAC OS X should update as quickly as possible because file based vulnerabilities have been a favorite of attackers in the last year.

References: