Risk
12/22/2010
10:51 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Microsoft Moves To Block Zero Day Attack

A French IT security firm recently warned of a new vulnerability that opens most versions of Microsoft Internet Explorer open to attack.

A French IT security firm recently warned of a new vulnerability that opens most versions of Microsoft Internet Explorer open to attack.Should a successful hack be launched, the attacker could circumvent many of the defenses available in both Windows Vista and Windows 7. The attacker could also run code of their choice on the target system.

To make the situation more pressing, the Metasploit project recently added an exploit to its database that successfully evades Microsoft's ASLR (Address Space Layout Randomization) and bypass DEP (Data Execution Prevention) defenses.

In an e-mail to InformationWeek, Microsoft noted that there is currently no indication that customers are being attacked. Late this evening, Microsoft's Security Research & Defense blog posted an update and mitigation guidance for the vulnerability.

Microsoft provided some details on the exploit:

The Metasploit project recently published an exploit for this vulnerability using a known technique to evade ASLR (Address Space Layout Randomization) and bypass DEP (Data Execution Prevention).

In a few words, Internet Explorer loads mscorie.dll, a library that was not compiled with /DYNAMICBASE (thus not supporting ASLR and being located always at the same base) when processing some html tags. Attackers use these predictable mappings to evade ASLR and bypass DEP by using ROP (return oriented programming) gadgets from these DLLs in order to allocate executable memory, copying their shellcode and jumping into it. Note that without that predictable mapping, the only public ways to evade ASLR and DEP is through:

• Use of this (in case the current vulnerability allows) or another vulnerability as an information leak.

• Using techniques such as JIT-spraying or similar ones. Please note IE only JITs IE9's javascript and there are security mitigations in place. But third party plugins could JIT in an insecure manner.

The same post recommends users employ Enhanced Mitigation Experience Toolkit (EMET) to block the threat. According to Microsoft, by using EMET, the associated mandatory ASLR, Heap Spray pre-allocation, and EAT Filtering will all mitigate the risk associated with this attack.

Microsoft also has more information in Security Advisory 2488013.

For my security and technology tweets throughout the day, find me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-1291
Published: 2015-09-03
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check whether a node is expected, which allows remote attackers to bypass the Same Origin Policy or cause a denial of service (DOM tree corruption) via a web s...

CVE-2015-1292
Published: 2015-09-03
The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy by accessing a Service Worker.

CVE-2015-1293
Published: 2015-09-03
The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

CVE-2015-1294
Published: 2015-09-03
Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering the use of matrix elements that lead to an...

CVE-2015-1295
Published: 2015-09-03
Multiple use-after-free vulnerabilities in the PrintWebViewHelper class in components/printing/renderer/print_web_view_helper.cc in Google Chrome before 45.0.2454.85 allow user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact by triggering nested IPC m...

Dark Reading Radio
Archived Dark Reading Radio
Another Black Hat is in the books and Dark Reading was there. Join the editors as they share their top stories, biggest lessons, and best conversations from the premier security conference.