Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

June 11th, 2007, 13:23 GMT · By

Windows Vista Security Updates Infested with Malware

SHARE:

Adjust text size:



Enlarge picture
With the monthly Microsoft patch cycle drawing near, fake security updates addressing a vulnerability in the company's latest operating system, Windows Vista, spammed in connection with the security updates scheduled for June 12 2007, are infested with malware. According to F-Secure, at the end of May, emails masquerading as a security update for Windows Vista and various other titles of the Windows platform are designed to infect users with Backdoor:W32/VanBot.CA. The Redmond Company's monthly security bulletin cycle is exploited and used as incentive to
spread malware.

The spammed emails seem to originate from Microsoft Support, and even feature the support@microsoft.com address, containing information of an actual vulnerability affecting Windows 2000, Windows XP, Windows Server 2003 and Windows Vista. Among the seven vulnerabilities in GDI, there is also the Windows Animated Cursor Handling flaw, rated with a severity rating of critical by Microsoft and patched in April 2003.

The first clue pointing to the fact that the email alleging to be a security update notification from Microsoft is a fake is the actual message. "Critical WMF-Exploit patch. In program maintenance of Microsoft corporation, a critical vulnerability has been found in processing WMF-files. Exploits using the "SetAbortProc" GDI function were discovered in May 2007. The function, which registers an error handler normally intended for use when a print job is canceled during spooling, allows arbitrary code added to a WMF image to be executed without the permission of the user," reds a fragment of the text.

Additionally, there is no text formatting that would give a hint to whether this is a valid Microsoft update or not. There is no reference to the official "Security Bulletin MS07-017" designed to patch the GDI vulnerabilities. The email also contains a direct download link to an .exe file, and promises to update Windows 98. As Windows 98 is no longer supported by Microsoft, users will no longer receive security updates. At the time of this article, F-Secure had already revealed that the malicious file was no longer in its initial location.

TELL US WHAT YOU THINK:

3,041 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Update - Windows Vista Expiration

The First Screenshot from Windows Vista Service Pack 1

Find Out Which Edition of Vista Can Only Boot, But Cannot Run Any Applications or Games!!!

Did Microsoft Lose the Windows Media Center Remote on the Way to Vista?

Side by Side Comparison: Windows Vista Starter, Home Basic, Home Basic N, Home Premium, Business, Business N, Enterprise and Ultimate

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM