September 30, 2006 4:27 PM PDT
Cybercrooks add Windows flaw to arsenal
- Related Stories
-
Security pros patch older Windows versions
September 30, 2006 -
Another zero-day threat hits Windows
September 29, 2006 -
Zero-day attacks continue to hit Microsoft
September 27, 2006 -
Trojan delivers unwanted gift to Windows PCs
December 28, 2005
Cybercrooks have started exploiting a flaw in the Windows Shell only days after sample attack code for the vulnerability surfaced. Web sites that exploit the vulnerability are popping up and attempt to load malicious software onto vulnerable Windows PCs in a way that is undetectable to users, experts said.
"There are professionals at work using the exploit code," security firm Websense said in an alert. The miscreants taking advantage of the flaw appear to be part of the same group that in December used another Windows flaw to hoist spyware onto PCs, Websense said. That flaw stemmed from the way Windows handled Windows Metafile, or WMF images.
Microsoft warned of the Windows Shell flaw on Thursday. The flaw affects Windows 2000, Windows XP and Windows Server 2003, and could be exploited via the Internet Explorer Web browser through a component called WebViewFolderIcon, the company said. Windows Shell is the part of the operating system that presents the user interface.
"The fact that they are using the exploit code poses a significant risk" in particular, because these sophisticated attackers are known to attract users to their sites via search engines and e-mail spam campaigns, Websense said.
The CoolWebSearch gang has also adopted the new flaw as a way to compromise systems, said Roger Thompson, chief technology officer at security software maker Exploit Prevention Labs. "It's not the end of the world or anything but it's an interesting escalation," he said.
CoolWebSearch is notorious for installing spyware and other malicious programs onto people's PCs. The group lures people to their sites via links in other search engines as well as by persuading Web masters to adopt their search engine, promising a lot of site visitors.
The Windows Shell flaw was found almost two months ago, but sample attack code became available only recently. Microsoft plans to issue a fix for the problem on Oct. 10, its regularly scheduled patch day, it said in a security advisory on Thursday.
Windows users can protect themselves by following the guidance Microsoft gives in its advisory, switching to a non-Microsoft Web browser, or installing security software such as Exploit Prevention Labs' SocketShield.
Also, a group of security professionals, calling itself the Zeroday Emergency Response Team, or ZERT, is working on a third-party fix that should be available before Microsoft's official patch, Thompson said.
Meanwhile, there are several other security vulnerabilities in Microsoft products waiting to be fixed. Some of these flaws are already being used in cyberattacks, though not as widespread as the Windows Shell flaw or another Windows bug for which Microsoft rushed out a fix on Tuesday, according to security experts.





You get what you deserve.....
And how much money is being saved in your organization by
dealing with this issue? How much have you spent in the last
three years? Guess the cheaper hardware makes up for it.
NOT!!!
Of Course, it does provide a lot of employment for IT
professionals to repair and keep the Windows systems running.
And this is the company that wants to be the sole provider of your
computer's security..!!!
Are Window user really that naive..???
It will also have the added benefit of remove the scum from the gene pool, preferrably before they spawned.
Don't get me wrong, Linux is a great OS. It's my OS of choice for running web servers, SQL, etc. I'm not as crazy about Mac OSX and I think its security is overrated, but just because these Operating Systems are better than Windows in some aspects doesn't mean that they have the answer for everything.
"switching to a non-Microsoft Web browser"
AMEN
Exploit Code is OUT for a few days already.
Today is Oct 3rd, 2006.
BUT
Microsoft still wants to wait until Oct 10, 2006?
We're way past when will Microsoft ever learn as this clearly shows that they WILL NEVER LEARN!!!
Walt
- Looking for blacklists
-
by Seaspray0
October 3, 2006 8:54 AM PDT
- I'd like to find a good blacklist of all these websites that repeatedly attempt to exploit holes to install their garbage on computers. Perhaps Cnet will be willing to do a story on this, since they seem to mention these "miscreants" often.
-
Reply to this comment
View
reply
-
-
See all 29 Comments >>