NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


MMS Exploit Available for Windows Mobile

What is Microsoft waiting for?

By Marius Oiaga, Technology News Editor

2nd of January 2007, 15:26 GMT

Adjust text size:


The MMS exploit available for Windows Mobile targets a vulnerability that has been reported more than a half a year ago, according to Symantec. Back in August 2006, Collin Mulliner from
the Trifinite Group revealed that a malformed MMS message could permit an attacker to perform arbitrary code execution on a Windows Mobile device. Since then, Microsoft has failed to address the vulnerability, although Collin has confirmed the vulnerability and also released a functional exploit.

Ollie Whitehouse, a Symantec Security Response Researcher summarized the situation:

- There has been a publicly disclosed vulnerability for over six months now.
- There is no patch for this vulnerability.
- There is an exploit now out there.
- There is no easy way to patch the vulnerable devices due to the lack of auto updates (try explaining what a firmware update is to your parents).

As a firmware update from Microsoft is not available, Collin presented the following workarounds:

- WLAN notification flooding denial of service - Packet filter / firewall on phone.

- MMS message-based attacks (the SMIL exploit) - IDS / "AntiVirus" on phone - Mobile phone service provider based IDS / "AntiVirus."

- General SMS/MMS Service Provider Measures - Filter binary SMS that carry MMS Mnotification.ind.

According to Collin, a Windows Mobile user needs only to view a malicious message in order to allow for a successful exploit. Microsoft has failed to comment the situation in any manner.
Read by 1,478 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.7/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Unveills AURA Mobile Tagging

IE7 Speaks Chinese and Hebrew

Microsoft to Synchronize with Ford

Microsoft and the Telecommunications Industry in the Telco 2.0 Era

Is "Live" the Right Brand for Microsoft's Search?

Microsoft Exchange Hosted Services Blacklisted

Microsoft Launches Centro and Cougar

The Top Live Searches

$750 Orange Zune Goes Unsold

Microsoft Unveils Expression Studio

Download Rights Management Services Administration Toolkit with SP2

Microsoft SQL Server Is the Heart of Wireless Development

The Zune Phone

Microsoft Unveiled Visual Studio 2005 Team Foundation Server MSSCCI Provider

Download Exchange Server 2007

Microsoft Is a Leader of the SSL VPN Market

OneCare-A Leader on the Security Market?

The First Update for Internet Explorer 7

Microsoft and HP to Partner over Enterprise Software

Microsoft Introduces Office PerformancePoint Server 2007 CTP

Microsoft Unveils XNA Game Studio Express

Windows Print Spooler 0day DoS Vulnerability

The First Public WPF/E Game

Put the YOU in Microsoft

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM