Vulnerabilities / Threats

7/9/2009
05:58 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Microsoft Fix For 'Browse-And-Get-Owned' Flaw Coming Tuesday

Two zero-day vulnerabilities, one reported last week, will be fixed in Microsoft's monthly patch release next week.

Moving with uncharacteristic speed, Microsoft plans to fix what it has called a "browse-and-get-owned" vulnerability in its Video ActiveX Control when it releases its July software patches next week.

The company acknowledged the vulnerability last week. It is also planning to fix a second "browse-and-get-owned" vulnerability in its DirectShow software that was disclosed in May.

Both of these flaws affect older version of Windows; Windows Vista and Windows Server 2008 are not affected.

'[O]ur engineering teams have been working around the clock to produce an update for [the Microsoft Video ActiveX Control vulnerability] and we believe that they will be able to release an update of appropriate quality for broad distribution that protects against the attacks we detailed in the advisory," said Jerry Bryant, senior security program manager at Microsoft, in a blog post on Thursday.

Microsoft said in an advanced summary of its upcoming July 14 security patch that it plans to release six security bulletins.

Three will be "critical" updates for Windows, one of which affects Windows Vista and Windows Server 2008. There will also be one "important" update for Publisher, one "important" update for Internet Security and Acceleration (ISA) Server, and one "important" update for Virtual PC and Virtual Server.

Security vendors Trend Micro and Websense have noted that the ActiveX flaw is being actively exploited on Web sites in China.

"Around 967 Chinese Web sites are reported to be infected by a malicious script that leads users to successive site redirections and lands them to download a .JPG file containing the exploit," said Trend Micro security engineer Roland Dela Paz in a blog post.

And Bryant said that Microsoft is aware of limited attempts to exploit the DirectShow vulnerability.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
BlueBorne Attack Highlights Flaws in Linux, IoT Security
Kelly Sheridan, Associate Editor, Dark Reading,  12/14/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security: 2017
A look at the biggest news stories (so far) of 2017 that shaped the cybersecurity landscape -- from Russian hacking, ransomware's coming-out party, and voting machine vulnerabilities to the massive data breach of credit-monitoring firm Equifax.
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.