Technology news and Jobs
Our Blogs
The BeerFiles
Microsoft finally admits fault for PDF attacks
Our Blogs
The BeerFiles
Microsoft finally admits fault for PDF attacks | Microsoft finally admits fault for PDF attacks |
|
|
|
| Written by Stan Beer | |
| Saturday, 27 October 2007 | |
|
Microsoft security response team member Bill Sisk issued a warning via the Microsoft Response Centre Blog yesterday admitting that applying a security update from Adobe does not fix the vulnerability and Microsoft is working feverishly to patch the flaw. "Third party applications are currently being used as the vector for attack and customers who have applied the security updates available from these vendors are currently protected. However, because the vulnerability mentioned in this advisory is in the Microsoft Windows ShellExecute function, these third party updates do not resolve the vulnerability – they just close an attack vector," wrote Sisk. "As part of our SSIRP process we currently have teams worldwide who are working around the clock to develop an update of appropriate quality for broad distribution. Because ShellExecute is a core part of Windows, our development and testing teams are taking extra care to minimize application compatibility issues." According to Finnish security company, F-Secure , an unknown party has been sending out tens of thousands of mails with subject-lines like: Your credit report; Personal Financial Statement; Your Credit File; and Balance Report. The mails contain no mail body, only an attachment called "report.pdf". When opened, the PDF file uses the CVE-2007-5020 vulnerability via Acrobat Reader and IE7 and downloads further malware from a server in Malaysia. The target of the malware seems to be to create a botnet of infected machines to be used for further malicious activity. F-Secure writes on its site. "We're worried about this case, as PDF attachments are typically not filtered at email gateways", says F-Secure's Chief Research Officer Mikko Hypponen. "Executable files are now stripped almost everywhere, but PDF is stripped almost nowhere". "Also, a security update for Acrobat Reader was just made available few days ago, so there are tons of users who haven't had a chance to update yet". As always, advisors say the best way to protect yourself is not to open dodgy emails. Could another way possibly be to migrate from Windows to something else - say Linux?
Get stories like this delivered daily - FREE - subscribe now When you subscribe get a 12 months license for LiveProject Valued at $99 USD |
| < Prev | Next > |
|---|



Tags


Subscribe to iTWire's daily e-newsletter now and get a FREE 12 month license to project management software valued at $99 USD. 




