Vulnerabilities / Threats
11/8/2013
12:43 PM
50%
50%

Criminals Exploit Microsoft Office Zero-Day Flaw

At least two sets of attackers have been using malicious Office documents to exploit the graphics processing vulnerability.

Windows 8.1: A Visual Tour
Windows 8.1: Visual Tour
(click image for larger view)
Warning: Attacks against a zero-day vulnerability in Microsoft Office are more extensive than first believed. That finding further reinforces security experts' recommendation that businesses install an emergency mitigation technique released by Microsoft as quickly as possible.

At least two different criminal groups appear to have been successfully targeting the zero-day bug, using malicious Office documents. The flaw has been traced to a remote-code execution vulnerability in Microsoft graphics functionality that handles the TIFF file format.

What's the risk? "An attacker could exploit this vulnerability by convincing a user to preview or open a specially crafted email message, open a specially crafted file, or browse specially crafted Web content," according to a Microsoft security advisory. "An attacker who successfully exploited the vulnerability could gain the same user rights as the current user," and execute arbitrary code or install malware.

[ Do you still use Windows XP? Read Windows XP Security Apocalypse: Prepare To Be Pwned. ]

Pending a patch, Microsoft has released an emergency "Fix it" that fully mitigates the vulnerability. Given the lack of lead time, security experts don't expect a patch for the zero-day vulnerability -- discovered this week -- to be ready for inclusion in this month's regularly scheduled Microsoft patch release, which is due to happen Tuesday.

To date, related attacks have targeted users of Microsoft Office 2003, 2007 and 2010, and targeted organizations have reportedly received booby-trapped Office documents. The graphics vulnerability is being exploited in a novel way: "We found the DEP status was 'on' at the process start but 'off' during shellcode execution,'" said Vinay Karecha, a McAfee Labs researcher, in a teardown of exploit code that refers to the advanced attack mitigation attack known as data execution prevention, which together with address space layout randomization (ASLR) has made Windows much more difficult for malware-writers to exploit.

"Our analyzed exploit didn't bypass ASLR and DEP," said Karecha. "Instead, it leveraged a backward-compatibility feature in Office 2007 to disable DEP. Without DEP, ASLR is quite easy to bypass."

According to FireEye researcher Mike Scott, one of the two groups that's been exploiting this zero-day vulnerability appears to be operating from India. "Our analysis has revealed a connection between these attacks and those previously documented in Operation Hangover, which adds India and Pakistan into the mix of targets," he said in a blog post. "Information obtained from a command-and-control server (CnC) used in recent attacks leveraging this zero-day exploit revealed that the Hangover group, believed to operate from India, has compromised 78 computers, 47 percent of those in Pakistan."

Norwegian security software vendor Norman was the first to highlight Operation Hangover in May, saying the Hangover group had been launching advanced persistent threat (APT) attacks since at least 2010. Norman also found multiple references in the malware code to Indian information security software and "ethical hacking" vendor Appin. Some security experts alleged that was a smoking gun that tied the APT attacks to Appin, and that the Hangover group's list of government targets in Pakistan suggests the Indian government might have commissioned the attacks. But Appin has continued to vigorously deny that it had any role in the attacks.

A second group, meanwhile, has been using the Microsoft graphics vulnerability to infect targeted PCs with Citadel malware, which is designed to steal financial information. "This group, which we call the Arx group, may have had access to the exploit before the Hangover group did," said FireEye's Scott. "Information obtained from CnCs operated by the Arx group revealed that 619 targets (4,024 unique IP addresses) have been compromised. The majority of the targets are in India (63%) and Pakistan (19%)."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3407
Published: 2014-11-27
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCuq68888.

CVE-2014-4829
Published: 2014-11-27
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authentication of arbitrary users for requests tha...

CVE-2014-4831
Published: 2014-11-27
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.

CVE-2014-4832
Published: 2014-11-27
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.

CVE-2014-4883
Published: 2014-11-27
resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?