Risk
12/22/2010
10:51 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Microsoft Moves To Block Zero Day Attack

A French IT security firm recently warned of a new vulnerability that opens most versions of Microsoft Internet Explorer open to attack.

A French IT security firm recently warned of a new vulnerability that opens most versions of Microsoft Internet Explorer open to attack.Should a successful hack be launched, the attacker could circumvent many of the defenses available in both Windows Vista and Windows 7. The attacker could also run code of their choice on the target system.

To make the situation more pressing, the Metasploit project recently added an exploit to its database that successfully evades Microsoft's ASLR (Address Space Layout Randomization) and bypass DEP (Data Execution Prevention) defenses.

In an e-mail to InformationWeek, Microsoft noted that there is currently no indication that customers are being attacked. Late this evening, Microsoft's Security Research & Defense blog posted an update and mitigation guidance for the vulnerability.

Microsoft provided some details on the exploit:

The Metasploit project recently published an exploit for this vulnerability using a known technique to evade ASLR (Address Space Layout Randomization) and bypass DEP (Data Execution Prevention).

In a few words, Internet Explorer loads mscorie.dll, a library that was not compiled with /DYNAMICBASE (thus not supporting ASLR and being located always at the same base) when processing some html tags. Attackers use these predictable mappings to evade ASLR and bypass DEP by using ROP (return oriented programming) gadgets from these DLLs in order to allocate executable memory, copying their shellcode and jumping into it. Note that without that predictable mapping, the only public ways to evade ASLR and DEP is through:

• Use of this (in case the current vulnerability allows) or another vulnerability as an information leak.

• Using techniques such as JIT-spraying or similar ones. Please note IE only JITs IE9's javascript and there are security mitigations in place. But third party plugins could JIT in an insecure manner.

The same post recommends users employ Enhanced Mitigation Experience Toolkit (EMET) to block the threat. According to Microsoft, by using EMET, the associated mandatory ASLR, Heap Spray pre-allocation, and EAT Filtering will all mitigate the risk associated with this attack.

Microsoft also has more information in Security Advisory 2488013.

For my security and technology tweets throughout the day, find me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4467
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.

CVE-2014-4476
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4477
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4479
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4480
Published: 2015-01-30
Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.