On mySimon: Victoria's Secret Vanilla Orchid
BNET Business Network:
BNET
TechRepublic
ZDNet

March 30th, 2007

Microsoft knew of Windows .ANI flaw since December 2006

Posted by Ryan Naraine @ 9:46 am

Categories: Botnets, Browsers, Data theft, Exploit code, Firefox, Hackers, Microsoft, Mozilla, Patch Watch, Pen testing, Responsible disclosure, Rootkits, Spam and Phishing, Spyware and Adware, Uncategorized, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Security, Microsoft Outlook, Determina Inc., Flaw, Vulnerability, Microsoft Windows, Microsoft Corp., Attack, Ryan Naraine

A private security research outfit says it notified Microsoft about the animated cursor (.ani) code execution vulnerability since December 2006, a full four months ahead of yesterday’s discovery of Internet Explorer drive-by attacks.

According to Alexander Sotirov, chief reverse engineer at Determina, his research team discovered and reported the flaw to Microsoft last December. On January 3, 2007, Microsoft reserved CVE-2007-0038 to use in its security bulletin.

So far this year, Microsoft has shipped 16 bulletins to fix a wide swathe of software vulnerabilities, but the animated cursor bug remains unpatched.

A Redmond spokesman confirmed that Determina responsibly disclosed the details of this flaw since last year. “We have been working with Determina since their report in December to investigate the issue and develop a comprehensive update to address the issue,” the spokesman said.

So, why has it taken so long to provide protection to Windows users? Microsoft explains:

Creating security updates that effectively fix vulnerabilities is an extensive process involving a series of sequential steps. There are many factors that impact the length of time between the discovery of a vulnerability and the release of a security update, and every vulnerability presents its own unique challenges. When a potential vulnerability is reported, designated product specific security experts investigate the scope and impact of a threat on the affected product. Once the MSRC knows the extent and the severity of the vulnerability, they work to develop an update for every supported version affected. Once the update is built, it must be tested with the different operating systems and applications it affects, then localized for many markets and languages across the globe.

Meanwhile, Determina warns that the vulnerability is “trivially exploitable on all versions of Windows, including Vista.

The protected mode of IE7 will lessen the impact of the vulnerability, but shellcode execution is of course still possible. Determina also discovered
that under certain circumstances Mozilla Firefox uses the same underlying Windows code for processing ANI files, and can be exploited similarly to Internet Explorer.

This is a fast-moving story with multiple angles. Here are some important things to pay attention to:

** eEye Digital Security, a research firm that found an almost identical bug in 2005 (see MS05-002), is offering a free third-party patch. eEye’s interim patch comes with source code. This patch is buyer-beware so use at your own risk.

** The only workaround guidance from Microsoft is to read e-mail messages in plain text format if you are using Outlook 2002 or a later version, or Windows Mail to help protect yourself from the HTML e-mail preview attack vector. However, reading e-mail in plain text on Windows Vista Mail does not mitigate attempts to exploit the vulnerability when Forwarding and Replying to mail sent by an attacker.

** For Users of Outlook Express, using plain text is not an effective mitigation and users should be extremely careful when reading mail from untrusted or malicious sources.

** In addition to IE, e-mail is a nasty attack vector because an attack can be launched silently if the target simply opens a specially crafted HTML message. However, users of Outlook 2007 are at not at risk from the HTML or Preview Pane attack vectors when using Word as their default editor or reading e-mail in plain text. Users of Outlook 2002 (with Office XP Service Pack 1 or a later version) and Outlook 2003 can enable the setting to read mail as plain text to successfully mitigate against attacks using the HTML or Preview Pane attack vectors.

** Mark Miller, director of the MSRC (Microsoft Security Response Center) tells me the in-the-wild attacks are still “very limited and targeted” but this could change quickly because exploit code that gives attackers a roadmap to exploit the flaw is publicly available. If the attacks escalate, Microsoft will consider an out-of-band emergency patch.

** This vulnerability does affect Windows Vista. However, Miller believes there are several mitigations that will reduce the risk for Vista users. These include Internet Explorer 7 in Protected Mode and UAC (User Account Control) which gives the user a pop-up warning ahead of an exploit. This is the first in-the-wild exploit that’s available for Windows Vista.

** The SANS Internet Storm Center has published a list of hostile domains hosting drive-by exploits.

** WebSense and others have found frightening similarities to the Super Bowl Web site breach earlier this year. This highlights just how widespread this could become if certain high-traffic sites or advertising networks are hijacked and seeded with malicious code.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 73 Talkback(s)
It's got nothing to do with the window manager.
X11 is not really that secure a window system. The X11 server runs as root, and with a very rich protocol. Window system crashes from badly behaved applications are a fact of life for UNIX GUI develop... (Read the rest)
Posted by: Resuna Posted on: 06/04/07 You are currently: a Guest | | Terms of Use
Don't be so tough on Microsoft  Yagotta B. Kidding | 03/30/07
Ahh, that way...  gfeier | 03/30/07
That is based on an assumption  dragosani | 03/30/07
Silly question  Yagotta B. Kidding | 03/30/07
And?  dragosani | 03/30/07
Which doesn't change the fact  Yagotta B. Kidding | 03/30/07
Which doesn't absolve  dragosani | 03/30/07
Full Discuolsure, this is why.  Mr L | 04/09/07
MS has a million and one reasons why they can't turn out patches in a  DonnieBoy | 03/30/07
Look: DB's "quote of the week"  John Zern | 03/30/07
Duct tape and bailing describes it quite well. Why else would it take them  DonnieBoy | 03/30/07
To test it to make sure it doesn't break hundreds of applications.  osreinstall | 04/01/07
To Test  Flying Pig | 04/02/07
Linux is truely the Operating System  GuidingLight | 03/30/07
You should save yourself the "embaresment" and learn how to spell.  DonnieBoy | 03/30/07
Ah, thank you for being a good little spell checker  GuidingLight | 03/30/07
As I said, there are very few that use Windows when the highest level of  DonnieBoy | 03/31/07
Pot, Kettle, Black  M.R. Kennedy | 04/01/07
Oh?  bitfuzzy | 03/31/07
Say what!?!?!  linux for me | 03/31/07
only if  Suicida| | 04/01/07
It's not working  CobraA1 | 03/31/07
These are one of the reasons...  ju1ce | 03/30/07
Yah well  zkiwi | 03/30/07
Not a browser problem!!!  linux for me | 03/30/07
And yet  zkiwi | 03/30/07
Why should the browser automatically open ANI files?  Resuna | 04/02/07
Firefox is also vulnerable to ANI flaw  qmlscycrajg | 03/31/07
Check this story:  msalzberg | 03/31/07
Firefox is also vulnerable to ANI flaw  qmlscycrajg | 03/31/07
Windows not safe on the internet  Chad_z | 03/30/07
ROTFL  John Zern | 03/30/07
Not surprised....  linux for me | 03/31/07
From the excuses MS is giving, either the code is one big hair ball,  DonnieBoy | 03/30/07
Here is another thought  mdemuth | 03/30/07
If I may quote...  msalzberg | 03/30/07
If *I* may quote...  M.R. Kennedy | 04/01/07
John knows . . .  brian ansorge | 04/03/07
Still impressed with MS's security improvements, George Ou?  ejhonda | 03/30/07
He should be  PB_z | 03/31/07
In what way?  Cardinal_Bill | 03/31/07
Maybe proud was the wrong word  PB_z | 04/01/07
In a way...  Cardinal_Bill | 04/01/07
Windows? Defense in depth? Ha ha ha ha!  Resuna | 04/02/07
No need for Vista users to worry  Paco20 | 03/30/07
But on the flip side  John Zern | 03/30/07
John Zern-Self Certified MS Cheerleader (NT)  Joseph Gerbils | 03/31/07
My Debian Install  Ole Man | 03/31/07
I've never heard...  msalzberg | 03/31/07
What?  SquishyParts | 04/01/07
YOU are the one person I see saying that  mdsmedia | 04/02/07
Whare are you smoking?  jared@... | 04/02/07
It's been how long?  o0splitpaw0o | 03/31/07
And we hear George Ou singing in the distance...  TechExec2 | 03/31/07
Wonder...  handydan918 | 03/31/07
Quartet members?  An_Axe_to_Grind | 03/31/07
For security, you can?t beat Mac OS X  mlindl | 03/31/07
Wait a minute  eye4bear | 04/01/07
Yup  mlindl | 04/01/07
No...Apple PATCHED the holes...  mdsmedia | 04/02/07
The queen was in the parlor...  jared@... | 04/02/07
To a degree  Boot_Agnostic | 04/02/07
A pity there are so few of you lot around...  HypnoToad72 | 04/06/07
MS had plenty of time to focus on this  Boot_Agnostic | 03/31/07
MS had plenty of time .  I'm Ye, the MS SHILL . | 04/01/07
that article was posted on BBC on March 30th  mdsmedia | 04/02/07
Sounds like politics  jim.bassett@... | 04/02/07
NOW will you listen, Microsoft?  Resuna | 04/02/07
Desktop-browser integration ok  cls@... | 04/02/07
It's got nothing to do with the window manager.  Resuna | 06/04/07
MSFT listens, just not to you.  cls@... | 04/02/07
This is an excerpt...  interested_amateur@... | 04/03/07
Microsoft MUST rule the SOFTWARE world!  nomorems | 04/07/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads