Showing posts sorted by relevance for query Security Bulletin. Sort by date Show all posts
Showing posts sorted by relevance for query Security Bulletin. Sort by date Show all posts

Microsoft Released Emergency Patch Fix To Block Duqu Zero-Day exploit


Microsoft released emergency patch to fix the newly found zero-day exploit in windows kernel. The attack, discovered by Hungarian researchers, exploits a vulnerability in Windows' TrueType font engine. A full fix for the problem is still pending, and will not be part of Microsoft's "Patch Tuesday" fixes for November. In the company's security advisory Microsoft said that attackers exploiting the TrueType vulnerability—which Duqu exploited through a Microsoft Word document—could gain access to the Windows kernel and run shell code. "The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights," Microsoft's statement said.
As a temporary workaround, Microsoft recommends shutting off access to T2EMBED.DLL, the dynamic link library that allows applications to display TrueType fonts. While the fix will prevent attacks, it also means that fonts won't display properly in applications. But Microsoft's security team sees the threat from Duqu as limited, stating that "overall, we see low customer impact at this time."
  • To know about the Microsoft Security Bulletin Advance Notification for November 2011 click Here
  • To download the emergency patch released by Microsoft click Here 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Working To Patch New 0-day Windows Kernel Vulnerability Associated With Duqu

 
Microsoft confirmed on Tuesday that it is working to patch a flaw found in the Duqu malware. Security researchers discovered a previously unknown Windows kernel vulnerability inside the infamous Duqu malware. CrySyS, the group who originally discovered the malware, warned on Tuesday that the malware contains a dropper file with a Microsoft 0-day kernel exploit inside. The exploit could allow malicious users to remotely execute code on an infected system. Microsoft confirmed the vulnerability on Tuesday. Microsoft is working on a security advisory for the issue. “We are working to address a vulnerability believed to be connected to the Duqu malware,” said a Microsoft spokesperson. The software giant is expected to issue a full security bulletin shortly.


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Adobe release patch for Flash Player to prevent XSS


Adobe has released an out-of-cycle security update for Flash Player just days after learning of a new zero-day vulnerability. The vulnerability affected Flash Player 10.3.181.16 and earlier versions on Windows, Macintosh, Linux and Solaris, and Android version 10.3.185.22 and earlier. Despite the speed of the patch release, the vulnerability did not get the top "critical" rating, but is still rated "important". The "important" status denotes a vulnerability which could compromise data security, allowing hackers access to confidential data, or could compromise processing resources in a user's computer. "This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user's behalf on any website or webmail provider, if the user visits a malicious website," Adobe said in a security bulletin. According to Adobe, the vulnerability is being exploited in the wild, in active, targeted attacks tricking the user into clicking on a malicious link delivered in an e-mail message. Adobe recommends users of the affected versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 10.3.181.22 or 10.3.181.23 for ActiveX. The firm expects to release an update for Flash Player 10.3.185.22 for Android later this week.
Adobe investigated the flaw in Adobe Reader and Acrobat versions 10.x and 9.x for Windows and Macintosh, but said it was unaware of zero-day attacks against those platforms.
Google has updated its Chrome web browser, also affected by the vulnerability.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Adobe Plugged Newly Found Zero-day Hole In Flash Player

Adobe Plugged Newly Found Zero-day Hole In Flash Player

Adobe warned that hackers are exploiting a critical vulnerability in its popular Flash Player program, and issued an emergency update to patch the bug. The vulnerability allows an attacker to crash the player or take control of an affected system. Adobe says that there are reports of this vulnerability being exploited in the wild as part of targeted email-based attacks which trick the user into clicking on a malicious file. Adobe released security updates for Adobe Flash Player 11.2.202.233 and earlier versions for Windows, Macintosh and Linux, Adobe Flash Player 11.1.115.7 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.8 and earlier versions for Android 3.x and 2.x. These updates address an object confusion vulnerability (CVE-2012-0779) that could cause the application to crash and potentially allow an attacker to take control of the affected system.
There are reports that the vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious file delivered in an email message. The exploit targets Flash Player on Internet Explorer for Windows only. 
Affected Software Version :- 
  • Adobe Flash Player 11.2.202.233 and earlier versions for Windows, Macintosh and Linux operating systems
  • Adobe Flash Player 11.1.115.7 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.8 and earlier versions for Android 3.x and 2.x
Adobe recommends users of Adobe Flash Player 11.2.202.233 and earlier versions for Windows, Macintosh and Linux update to Adobe Flash Player 11.2.202.235. Flash Player installed with Google Chrome was updated automatically, so no user action is required. Users of Adobe Flash Player 11.1.115.7 and earlier versions on Android 4.x devices should update to Adobe Flash Player 11.1.115.8. Users of Adobe Flash Player 11.1.111.8 and earlier versions for Android 3.x and earlier versions should update to Flash Player 11.1.111.9. For detailed information and to see the security bulletin of Adobe click here.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

DHS Bulletin: Anonymous & Associated Hacker Groups Deploying New Cyber Attack Tools


Department of Homeland Security (DSH) released a new bulletin A-0011-NCCIC -120020110914  (U//FOUO) saying that Anonymous and Associated hackers groups are developing and deploying new cyber attack tools. The bulletin contains brif of Anon, Their attacks on the Internet, cyber attack tools, exploits (LOIC, #RefRef, Apache Killer, URGE, Anonware) and so on. 

For More information and to download the bulletin Click Here






SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft plugs critical hole in Windows


Microsoft today fixed a critical hole in Windows and two less serious holes in Office in one of the lightest Patch Tuesdays in recent history.
The critical bulletin, MS11-035, fixes a vulnerability in the Windows Internet Name Service (WINS) that "could allow remote code execution if a user received specially crafted malware on an affected system running the WINS service," according to the bulletin advisory. It affects Windows Server 2003 and 2008.
WINS is not installed on the affected operating system software by default, so only customers who manually install it are affected and will be offered the update, Microsoft said.
"Microsoft is downplaying the bug, but there is potential here for remote code execution," and thus total control of the computer, said Andrew Storms, director of security operations at nCircle. "WINS is a network-aware application that does not require authentication, and many enterprises require WINS on their networks. Taken together, these factors mean that a lot of enterprises will find their internal network servers vulnerable to a remote code bug. Initially, most attackers will probably only trigger a DoS (denial-of-service) event, but finding the remote code exploit won't be far behind."
The second bulletin, MS11-036, fixes two vulnerabilities in Microsoft PowerPoint that could allow remote code execution if a user opens a malicious PowerPoint file. The vulnerabilities affect Office XP, Office 2003, Office 2007, Office 2004 for Mac, and Office 2008 for Mac.
Microsoft also changed its Exploitability Index, the guide it uses to provide customers information on how likely a vulnerability is of being exploited. The company will be publishing two ratings per vulnerability, one for the most recent platform and a second as an aggregate rating for all older versions of the software.
Patch Tuesday has been fairly hectic recently, including last month when 17 bulletins were released to fix 64 vulnerabilities.


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Analysis of an Osama bin Laden RTF Exploit

Targeted/semi-targeted attacks have been utilizing exploits against Microsoft's "RTF Stack Buffer Overflow Vulnerability" (CVE-2010-3333) since last December. The vulnerability was patched last November in security bulletin MS10-087.
Many of the attacks we've seen which exploit CVE-2010-333 have used topical subject lines.
And this week is no different. So of course, there's an Osama bin Laden RTF exploit circulating in the wild which uses the subject: "FW: Courier who led U.S. to Osama bin Laden's hideout identified".
The file name is called: "Laden's Death.doc" and appears as so
:
Courier who led U.S. to Osama bin Laden's hideout identified


When the RTF file is opened, the exploit executes shellcode and drops a file named server.exe inside C:/RECYCLER and executes it.

C:/RECYCLER/server.exe does the following:

  •  Drops a file in the system's temp folder: vmm2.tmp
  •  File vmm2.tmp is renamed and moved to c:\windows\system32\dhcpsrv.dll
  •  Makes registry modifications in an attempt to hijack the DHCP service.

It attempts to connect to a C&C hosted at ucparlnet.com.

The payload has the ability to:

  •  Download additional malware
  •  Connect and send sensitive data back to remote servers
  •  Act as a trojan proxy server

The folks at contagio malware dump report that "It was sent to many targets in the US Government today".

Checking our back end shows that some of our customers have also been exposed. Our detection name for the exploit is Exploit:W32/Cve-2010-3333.G and the RTF payload is detected as Trojan:W32/Agent.DSKA.

As always, the usual advice applies, exercise caution when opening attachments, patch/update your MS Word/Office, and make sure your antivirus is up to date.

You can see more examples of CVE-2010-3333 attacks at contagio.

Updated to add: Here's a picture of an email spreading this document. This was sent to analysts in Washington, D.C. The picture was published by Lotta Danielsson-Murphy. Do note that the sender information in the email is forged.

Laden's Death.doc

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

VB2011 (Virus Bulletin) Conference in Barcelona


Over its 19-year history, the VB conference has become a major highlight of the anti-malware calendar, with many of its regular attendees citing it as the anti-malware event of the year. The conference provides a focus for the industry, representing an opportunity for experts in the field to share their research interests, discuss methods and technologies and set new standards, as well as meet with - and learn from - those who put their technologies into practice in the real world.
Split into two streams, the conference program caters for both technical and corporate audiences, covering a wide range of anti-malware and spam-related subjects. Delegates range from dedicated anti-malware researchers to security experts from government and military organizations, legal, financial and educational institutions and large corporations worldwide.

VB2011 - Barcelona

VB2011 will take place 5 - 7 October 2011 at the Hesperia Tower hotel, Barcelona, Spain.

The VB2011 conference programme is available to browse, with full abstracts for each presentation - including the last-minute presentations - here

Online registration is now open. 

Click here to register online. 
 
If you prefer to register offline please download the registration form (PDF) here.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

PBS Hacked Again



The affected website was for the program "Becoming American." Bentley says a "very small number" of administrative user names and encrypted passwords were stolen.PBS spokeswoman Anne Bentley says one section of a website in the PBS collection of sites was defaced Friday. PBS says its website has been hacked for at least the second time in a month - the latest in a string of intrusions into such sites as Sony, Lockheed Martin, Nintendo and others.  At the end of May, hackers broke into the PBS website and posted a phony story claiming the late rapper Tupac Shakur was alive. A group that claimed responsibility complained about a recent "Frontline" investigation on Wikileaks.Arlington, Va.-based PBS says it has seen an increasing number of intrusion attempts recently. 


Apparently retaliating for a recent Frontline program about WikiLeaks, the group, which calls itself @LulzSec or The Lulz Boat, also disclosed passwords and e-mail addresses held by PBS on the public bulletin board Pastebin.com.Shakur died in a shooting in Las Vegas in 1996. Smalls, whose real name was Christopher George Latore Wallace, was gunned down the following year in a Los Angeles drive-by shooting.By Monday morning, the fake story, which had appeared on The RunDown under the byline PBS WebTech, was gone. But a cached version remains available:"Prominent rapper Tupac has been found alive and well in a small resort in New Zealand, locals report. The small town - unnamed due to security risks - allegedly housed Tupac and Biggie Smalls (another rapper) for several years. One local, David File, recently passed away, leaving evidence and reports of Tupac's visit in a diary, which he requested be shipped to his family in the United States."A hacker group posted a bogus report on the PBS website on Saturday evening that claim slain rappers Tupac Shakur and Biggie Smalls were actually alive and residing in New Zealand.  
According to the Australian publication Secure Business Intelligence, LulzSec had earlier targeted Fox News and the X-Factor television show.
In explaining its motivation, "LulzSec" put out a statement:
"Greetings, Internets. We just finished watching WikiSecrets and were less than impressed. We decided to sail our Lulz Boat over to the PBS servers for further... perusing. As you should know by now, not even that fancy-ass fortress from the third shitty Pirates of the Caribbean movie (first one was better!) can withhold our barrage of chaos and lulz. Anyway, unnecessary sequels aside... wait, actually: second and third Matrix movies sucked too! Anyway, say hello to the insides of the PBS servers, folks. They best watch where they're sailing next time."

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...