NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Fresh Attacks Surface Targeting Windows Vista

Via Internet Explorer 7

By Marius Oiaga, Technology News Editor

22nd of June 2007, 15:39 GMT

Adjust text size:



Enlarge picture
Security company Symantec has warned of new attacks targeting Windows Vista via a critical vulnerability in Internet Explorer 7. The exploit is designed to speculate copies of the operating system that have not been patched with the security updates released by Microsoft on June 12, 2007. The Speech Control Memory Corruption vulnerability does not impact Windows Vista directly, but instead affects Internet Explorer 7, one of the components that ship by default with the operating system, but also previous versions of the browser. The risk is maximum
for exposed systems, as the flaw allows for remote code execution in the eventuality of a successful attack.

"What makes this case special is the fact that this is the first detected instance of in-the-wild exploitation of Microsoft Internet Explorer Speech API 4 COM Object Instantiation Buffer Overflow Vulnerability. This exploit appears to be a derivation of the publicly available exploit released at milw0rm.com. The malicious attacker can instantiate these COM objects via Internet Explorer, and pass overly long arguments to certain routines. In this case, the exploit passes a maliciously crafted argument (ModeName) to the DirectSS.FindEngine function. The overflowed buffer is then populated with attacker-supplied shellcode over-writing the Structured Exception Handler, thus resulting in the execution of arbitrary code," revealed Pukhraj Singh, Symantec Senior Threat Analyst.

Exploits for the IE Speech Control Memory Corruption vulnerability are served via a compromised website which also targets Xunlei, a Chinese peer-to-peer application. Both exploits feature the same payload. In this context, an attack would infect the computer with W32.Looked.BK, a network-aware worm created to compromise executable files on the local drives and across a network.

"Another interesting aspect of this attack was the clever JavaScript obfuscation techniques used to hide these attacks. At first glance, what appeared to be a garbled webpage turns out to be an obfuscated JavaScript exploit using up to six-levels of obfuscation (see image). This is primarily used to evade security products like web-application which implement on-the-fly script parsers," Singh added.

TAGS:

Windows Vista | Internet Explorer 7 | Symantec
Read by 1,453 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.7/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Update - Windows Vista Expiration

Windows Vista Hardcore Fan Names Newborn Girl... Vista

Windows Anytime Upgrade Kills Windows Vista

The Downsides of 64-bit Windows Vista

More Windows Vista Delays Coming

A Copy of Windows Vista Is Sold Every 4.5 Seconds

Windows Vista Hardware Assessment Tool Available

Windows XP Blind to Windows Vista on a Network

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM