Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Emergency Adobe Flash Player patch coming today


Less than a week after warning that hackers were embedding malicious Flash Player files (.swf) into Microsoft Word documents to launch targeted malware attacks, Adobe plans to release an emergency Flash Player patch today to fix the underlying problem.

The patch will fix a “critical” vulnerability in Flash Player 10.2.153.1 and earlier versions for Windows, Mac OS X Linux and Solaris.

According to this Secunia advisory, the flaw allows a hacker to completely hijack a vulnerable Windows computer:

A vulnerability has been reported in Adobe Flash Player, which can be exploited by malicious people to compromise a user’s system.

The vulnerability is caused due to an error when parsing ActionScript that adds a custom function to the prototype of a predefined class. This results in incorrect interpretation of an object (i.e. object type confusion) when calling the custom function, which causes an invalid pointer to be dereferenced.

Secunia has posted a technical analysis of the flaw as well.

Adobe has confirmed that the vulnerability (CVE-2011-0611) could cause a crash and potentially allow an attacker to take control of the affected system.

There are reports that this vulnerability is being exploited in the wild in targeted attacks via a malicious Web page or a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an email attachment, targeting the Windows platform. At this time, Adobe is not aware of any attacks via PDF targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.

A patch for Google Chrome users is already available in Chrome version 10.0.648.205.

Adobe plans to fix the vulnerability in Adobe Acrobat and Adobe Reader at a later date.

[Source: zdnet]

Oracle to patch 73 critical DB server flaws

The next batch of security patches from Oracle will be a biggie: 73 new security vulnerability fixes across hundreds of Oracle products.

According to an advance notice from the database server giant, some of the vulnerabilities affect multiple products and may be exploited over a network without the need for a username and password.

The patches, scheduled for release next Tuesday (April 19, 2011), will affect the following products and components:

Security vulnerabilities addressed by this Critical Patch Update affect the following products:

  • Oracle Database 11g Release 2, versions 11.2.0.1, 11.2.0.2
  • Oracle Database 11g Release 1, version 11.1.0.7
  • Oracle Database 10g Release 2, versions 10.2.0.3, 10.2.0.4, 10.2.0.5
  • Oracle Database 10g Release 1, version 10.1.0.5
  • Oracle Fusion Middleware 11g Release 1, versions 11.1.1.2.0, 11.1.1.3.0, 11.1.1.4.0
  • Oracle Application Server 10g Release 3, version 10.1.3.5.0
  • Oracle Application Server 10g Release 2, version 10.1.2.3.0
  • Oracle Identity Management 10g, versions 10.1.4.0.1, 10.1.4.3
  • Oracle JRockit, versions R27.6.8 and earlier (JDK/JRE 1.4.2, 5, 6), R28.1.1 and earlier (JDK/JRE 5, 6)
  • Oracle Outside In Technology, versions 8.3.2.0, 8.3.5.0
  • Oracle WebLogic Server, versions 8.1.6, 9.2.3, 9.2.4, 10.0.2, 11gR1 (10.3.2, 10.3.3, 10.3.4)
  • Oracle E-Business Suite Release 12, versions 12.0.6, 12.1.1, 12.1.2, 12.1.3
  • Oracle E-Business Suite Release 11i, version 11.5.10.2
  • Oracle Agile Technology Platform, versions 9.3.0.2, 9.3.1
  • Oracle PeopleSoft Enterprise CRM, version 8.9
  • Oracle PeopleSoft Enterprise ELS, versions 9.0, 9.1
  • Oracle PeopleSoft Enterprise HRMS, versions 9.0, 9.1
  • Oracle PeopleSoft Enterprise Portal, versions 8.8, 8.9, 9.0, 9.1
  • Oracle PeopleSoft Enterprise People Tools, versions 8.49, 8.50, 8.51
  • Oracle JD Edwards OneWorld Tools, version 24.1.x
  • Oracle JD Edwards EnterpriseOne Tools, version 8.98.x
  • Oracle Siebel CRM Core, versions 7.8.2, 8.0.0, 8.1.1
  • Oracle InForm, versions 4.5, 4.6, 5.0
  • Oracle Sun Product Suite
  • Oracle Open Office, version 3 and StarOffice/StarSuite, versions 7, 8

The highest CVSS 2.0 Base Score for vulnerabilities in this Critical Patch Update is 10.0 for Oracle JRockit of Oracle Fusion Middleware and Sun GlassFish Enterprise Server, Sun Java System Application Server of Oracle Sun Products Suite, the company said.

“Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update fixes as soon as possible.

[Source: zdnet]

Microsoft updates security advisory for local exploit for Windows Server



Microsoft updated Security Advisory (951306) last week. A vulnerability exists from last April that allowed local privilege escalation. The update to the advisory was made since there is now exploit code online. There is currently no patch available but a workaround is possible:

Microsoft is investigating new public reports of a vulnerability which could allow elevation of privilege from authenticated user to LocalSystem, affecting Windows XP Professional Service Pack 2, Windows XP Professional Service Pack 3, and all supported versions and editions of Windows Server 2003, Windows Vista, and Windows Server 2008. Customers who allow user-provided code to run in an authenticated context, such as within Internet Information Services (IIS) and SQL Server, should review this advisory. Hosting providers may be at increased risk from this elevation of privilege vulnerability.

Microsoft is aware that exploit code has been published on the Internet for the vulnerability addressed by this advisory. Our investigation of this exploit code has verified that it does not affect customers who have applied the workarounds listed below on their computers. Currently, Microsoft is not aware of active attacks that use this exploit code or of customer impact at this time. However, Microsoft is actively monitoring this situation to keep customers informed and to provide customer guidance as necessary. Upon completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through a service pack, our monthly security update release process, or an out-of-cycle security update, depending on customer needs

(Source: Microsoft Technet)

Updates and Task Manager Disabled by New Windows XP Worm

The Windows functions are always under attack because disabling a vital function of the operating system automatically means an open door for the hacker, who would be able to infiltrate into the computer and conduct his malicious activities. Today, a new worm has been spotted in the wild and, according to security company Trend Micro, it affects most flavors of the operating system produced by Microsoft, including Windows 98, ME, NT, 2000, XP and Server 2003.

But what's worse is that WORM_SILLYFDC.CY has a high damage potential
and a high distribution potential, two elements that underline the worm's capability to reach your computer and harm the data stored on it. In case you're curios about how can you get infected, the process is pretty simple: all you need to do is to visit an infected page. However, the worm may also be dropped by another piece of malware, Trend Micro explains.

The main targets of the worm are two important Windows functions: the Automatic Windows Update and the Task Manager. Both features of the operating system are disabled, so the users would not be able to update their Windows version or to check the running processes in order to shut down the infection.

The Windows Task Manager
Comments: The Windows Task Manager

Just like many other recent worms, WORM_SILLYFDC.CY spreads itself through the clean removable drives connected to the computer. Every time a removable drive is plugged into the system, the worm copies an Autorun.inf file to execute itself once the device is connect to another PC.

In addition, "it infects files of certain types. It does this by adding an iFrame tag that contains a link to a malicious site. As of this writing, the iFrame tag may contain a malicious URL," Trend Micro explains.

[Source: softpedia]

Malicious Behavior Threat Searching for Windows Stations

Although this month may appear to be a calm and quiet period because no new dangerous threats have appeared, there are a lot of reports concerning spyware, Trojan horses and
other type of infections that came out to find new vulnerable systems. But thanks to the security companies out there, our security products are able to spot and block them without allowing the infections to reach our valuable data.

Security company Sophos warned today that a new malicious behavior malware has been spotted in the wild but, at the moment, only a few details are available. All we know is that Mal/Behav-222 affects Windows computers but the security company didn't mention the affected file formats or the method the threat reaches the vulnerable computers.

"Mal/Behav-222 is a malicious program for the Windows platform," Sophos informs. Moreover, the security company asked users who believe that they got infected with Mal/Behav-222 to contact the firm in order to help the employees provide more information about the threat. "Detection for members of Mal/Behav-222 is behavior based. It is extremely important that customers report detections of Mal/Behav-222 to Sophos and send a sample for analysis," Sophos wrote.


The security of our computers is one of the aspects that shouldn't be neglected by any of you, because by using such a malicious tool, an attacker could get into the system and browse, copy or delete any file he wants to. That's why users are always advised to keep their antivirus solutions up-to-date with the latest virus definitions, apply the newest patches and fixes, and keep the security products enabled in order to spot and block any new threat spotted on the web. In addition, don't forget to deploy the latest software updates to avoid exploits and vulnerability attacks.

[Source: softpedia]