Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

10/23/2014
02:05 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Attacks On Patched Sandworm Flaw Force Microsoft To Issue Fix It

More than a week after Microsoft fixed a flaw affecting almost all Windows versions, attackers are continuing to exploit it.

Attackers have managed to bypass a security patch that Microsoft issued last week to address the recently discovered Sandworm vulnerability in Windows, prompting the company to issue another advisory this week, warning users of the new threat.

All supported versions of Windows, except Windows server 2003, continue to be vulnerable to attacks that attempt to exploit the vulnerability through rogue PowerPoint attachments, Microsoft noted earlier this week.

“An attacker who successfully exploited the vulnerability could gain the same user rights as the current user,” Microsoft warned. The company issued a temporary Fix It patch for mitigating exposure to the threat and encouraged users to apply it immediately.

The Sandworm vulnerability refers to a Windows packager zero-day flaw that basically gives attackers a way to take complete remote control of an infected system. Attackers typically have exploited the flaw using malicious PowerPoint files sent as innocuous attachments to unsuspecting users. When an infected PowerPoint file is opened, it drops a malicious payload on the system.

Russian cyber espionage gang Sandworm has used the exploit in numerous attacks against NATO, the Ukrainian government, and various targets in the US since 2013.

Microsoft last week issued a patch (MS14-060) to address the flaw, which exists in the Object Linking and Embedding (OLE) code within Windows.

However, several security vendors have reported seeing continued attacks seeking to exploit the same vulnerability in the days since Microsoft issued the patch.

In a blog post, Symantec said it has seen at least two groups of attackers that are continuing to take advantage of the Sandworm flaw by using an exploit that deftly sidesteps the Microsoft patch.

As with previous exploits, attackers are still using malicious PowerPoint documents to try and trick users into downloading malware on their systems, Symantec noted.

The new attacks are being used to deliver at least two different malicious payloads to victims. Symantec identified one of the payloads as Trojan.Taidoor and the other as Backdoor.Darkmoon or Poison Ivy.

The group using Taidoor has been around since at least 2008 and has a track record of exploiting new zero-day flaws, Symantec said. The Darkmoon variant, meanwhile, appears to have been ready for use several weeks before Microsoft disclosed the Sandworm vulnerability last week, Symantec added.

According to Trend Micro, with the new exploits, attackers are embedding the malicious files directly in the OLE object. So when a user opens an infected PowerPoint file, the malware is dropped directly on the system, instead of from a remote location.

“One advantage of this approach is that it will not require the computer to connect to the download location, thus preventing any detection from the Network Intrusion Prevention System (NIPS),” Trend Micro threat analyst Ronnie Giagone wrote on Trend Micro’s Security Intelligence blog.

McAfee security researcher Haifei Li said that Microsoft’s original patch for the Sandworm vulnerability might not have been “robust enough” to stop attackers from exploiting it. “In other words, attackers might still be able to exploit the vulnerability even after the patch is applied. Users who have installed the official patch are still at risk,” Li wrote on McAfee’s blog.

Users who are concerned about the threat should apply the Microsoft Fix It from this week’s advisory or apply the workarounds contained in the original MS14-060 bulletin from last week, Li said.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Overcoming the Challenge of Shorter Certificate Lifespans
Mike Cooper, Founder & CEO of Revocent,  10/15/2020
US Counterintelligence Director & Fmr. Europol Leader Talk Election Security
Kelly Sheridan, Staff Editor, Dark Reading,  10/16/2020
7 Tips for Choosing Security Metrics That Matter
Ericka Chickowski, Contributing Writer,  10/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-4564
PUBLISHED: 2020-10-20
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 and IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...
CVE-2020-4748
PUBLISHED: 2020-10-20
IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188517.
CVE-2020-4749
PUBLISHED: 2020-10-20
IBM Spectrum Scale 5.0.0 through 5.0.5.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link ...
CVE-2020-4755
PUBLISHED: 2020-10-20
IBM Spectrum Scale 5.0.0 through 5.0.5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188595.
CVE-2020-4756
PUBLISHED: 2020-10-20
IBM Spectrum Scale V4.2.0.0 through V4.2.3.23 and V5.0.0.0 through V5.0.5.2 as well as IBM Elastic Storage System 6.0.0 through 6.0.1.0 could allow a local attacker to invoke a subset of ioctls on the device with invalid arguments that could crash the keneral and cause a denial of service. IBM X-For...