Vulnerabilities / Threats
6/1/2011
09:56 AM
50%
50%

Microsoft Finds 5% Of PCs Running Malware

Java exploits predominate, including some still successfully targeting bugs from 2008.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
One in 20 PCs is infected with malware, according to statistics gathered by a free Microsoft scanning tool. Interestingly, the average infected PC contained 3.5 pieces of malware, and most of those malware applications exploited Java vulnerabilities.

Those findings come via Microsoft Safety Scanner (MSS), a free, recently updated tool from Microsoft that's designed to clean up after a malware infection. The tool expires 10 days after being downloaded to force users to download a new version with the latest updates.

After recently updating MSS to scan 64-bit Windows systems, Microsoft compiled seven days' worth of scans, and found that "seven of the top 10 threats are files containing exploits for Java vulnerabilities," according to a blog post from Scott Wu and Joe Faulhaber at the Microsoft Malware Protection Center.

The most-seen malware was OpenCandy adware, present on 0.8% of all PCs scanned. But almost every other piece of prevalent malware contained code for exploiting Java vulnerabilities, including a Java Runtime Environment (JRE) bug discovered in 2008.

To illustrate the types of malware its scanner found on PCs, Microsoft detailed the malware found just on the 0.5% of PCs exploited via the 2008 JRE bug: Alureon rootkit (on 7.3% of those PCs), browser modifier Zwangi (6.0%), rogue application Winwebsec (5.7%), and Hotbar and ClickPotato adware (both 5.4%).

"Of course many of these detections by MSS are the debris or aftermath after the exploit has already executed," said Wu and Faulhaber. "By the time a user downloads and runs MSS to detect malware, the machine may have already been infected, if it was vulnerable to the exploit at the time." That's why Microsoft says MSS is "not a replacement for using an antivirus software program that provides ongoing protection" and which could have prevented an infection in the first place.

This isn't the first time that Microsoft has trumpeted the threat posed by Java vulnerabilities. According to Microsoft's 2010 Security Intelligence Report, "exploits that use HTML and JavaScript steadily increased throughout the year and continue to represent a large portion of exploits." Notably, it found that "the most prevalent type of attack in this category involved malicious iFrames," which attackers often use after compromising a website, to then attack anyone who visits.

In 2011, the Java threat doesn't appear to have diminished. According to a study by Kaspersky Labs that looked at malware trends from January through March 2011, Java vulnerabilities comprised a significant portion of the top 10 "most seen" vulnerabilities on people's PCs. "Vulnerabilities in Adobe products occupied five positions in the list, including 1st and 2nd places, while 4th and 5th positions were taken up by vulnerabilities in the Java Virtual Machine," said Yury Namestnikov, a security researcher at Kaspersky, in a blog post. The remaining top 10 vulnerabilities involved Apple QuickTime, Winamp, and Microsoft Office.

"All of the vulnerabilities that appeared in the Top 10 enable cybercriminals to take control of computers at the system level," said Namestnikov.

Black Hat USA 2011 presents a unique opportunity for members of the security industry to gather and discuss the latest in cutting-edge research. It happens Aug. 3-4 in Las Vegas. Find out more and register.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0279
Published: 2015-03-26
JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.

CVE-2015-0635
Published: 2015-03-26
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, and consequently bypass intended device an...

CVE-2015-0636
Published: 2015-03-26
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN messages that reset a finite state machine,...

CVE-2015-0637
Published: 2015-03-26
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (device reload) via spoofed AN messages, aka Bug ID CSCup62315.

CVE-2015-0638
Published: 2015-03-26
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.