On mySimon: Issey Miyake Automatic Watch for Men
BNET Business Network:
BNET
TechRepublic
ZDNet

February 10th, 2009

Microsoft: 'Consistent exploit code likely' for IE vulnerabilities

Posted by Ryan Naraine @ 11:48 am

Categories: Arbitrary Code Execution, Botnets, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Exploit code, Malware, Microsoft, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research, Windows Vista

Tags: Vulnerability, Microsoft Exchange Server, Server, Exploit Code, Microsoft Internet Explorer, Microsoft Corp., E-mail Servers, Groupware, Web Browsers, Security

Microsoft today shipped four bulletins with patches for at least 8 documented security vulnerabilities affecting Windows users and warned that “consistent exploit code could be easily crafted” to launch attacks via the Internet Explorer browser.

The Patch Tuesday batch includes fixes for a pair of code execution holes in IE, two bugs in the Microsoft Exchange Server, a remote code execution issue in the Microsoft SQL Server, and three separate flaws haunting users of Microsoft Office Visio.

The Internet Explorer bulletin (MS09-002) should be treated with urgency because the flaws can be exploited to launch drive-by download attacks.

  • This security update is rated Critical for Internet Explorer 7 running on supported editions of Windows XP and Windows Vista. For Internet Explorer 7 running on supported editions of Windows Server 2003 and Windows Server 2008, this security update is rated Moderate.

The Microsoft warning that consistent exploit code was likely suggests that it’s very easy for an attacker to host a specially crafted Web site and attack unpatched users who surfed to the rigged Web site.

  • The attacker could also take advantage of compromised Web sites and Web sites that accept or host user-provided content or advertisements. These Web sites could contain specially crafted content that could exploit this vulnerability.

Enterprise administrators will also want to pay special attention to the Microsoft Exchange update (MS09-003) which covers two different vulnerabilities that expose users to code execution or denial-of-service attacks.

Microsoft explains:

  • The first vulnerability could allow remote code execution if a specially crafted TNEF message is sent to a Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could take complete control of the affected system with Exchange Server service account privileges. The second vulnerability could allow denial of service if a specially crafted MAPI command is sent to a Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could cause the Microsoft Exchange System Attendant service and other services that use the EMSMDB32 provider to stop responding.

The company says it expects to see “inconsistent exploit code” published for this bulletin.  However, nCircle director of security operations Andrew Storms says this is a very serious problem.

“This vulnerability means that any cybercriminal sending a well crafted email attachment to an enterprise could gain complete control over the server and gaining one of the keys to the kingdom,” Storms said.

“All kinds of highly confidential and proprietary information pass through an Exchange server every day.  Gaining control over it and its content would be a gold mine to any cyber criminal,” he added.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 162 Talkback(s)
RE: Microsoft: ?Consistent exploit code likely? for IE vulnerabilities
Recently seen a fresh install of XP SP3 just got NIC up and off to Activate / update before it gets hit, and boom AV2009 POP up from windows update site, I could not believe it. What a piece of C**P T... (Read the rest)
Posted by: xtrmgamr Posted on: 03/06/09 You are currently: a Guest | | Terms of Use
IE8 and Windows 7 aren't mentioned  NonZealot | 02/10/09
I agree  MGP2 | 02/10/09
I disagree  AzuMao | 02/11/09
What was I being sarcastic about?  NonZealot | 02/11/09
Don't worry!  Kid Icarus-21097050858087920245213802267493 | 02/10/09
True, OS X was the first to fall in PWN2OWN  NonZealot | 02/10/09
It's all good  Kid Icarus-21097050858087920245213802267493 | 02/10/09
It's very relevant.  ye | 02/10/09
Let it go...  Kid Icarus-21097050858087920245213802267493 | 02/10/09
Too bad that same courtesy is not extended to MS.  ye | 02/10/09
Have fun beatin that dead horse!  Kid Icarus-21097050858087920245213802267493 | 02/10/09
Re: Patched  MissingMatter | 02/10/09
Not quite  frgough | 02/10/09
It's the exact same type of exploit used to...  ye | 02/10/09
quite  rtk | 02/10/09
Right  AzuMao | 02/11/09
It wasn't relevant then.  kozmcrae | 02/10/09
This has got to be the stupidest defense I've ever read.  ye | 02/10/09
So let me get this straight  rtk | 02/10/09
A "stupid defense" works fine for Linux and OS X.  kozmcrae | 02/10/09
@kozmcrae: I use nothing more than Windows' built in...  ye | 02/11/09
"Never had a problem with malware."  kozmcrae | 02/11/09
Firefox on Windows 7 runs just great. (nt)  NonZealot | 02/10/09
Firefox...  Dave32265 | 02/11/09
Flash works fine on 32 bit Win7  NonZealot | 02/11/09
works fine on 64bit as well.  rtk | 02/11/09
64 bit...  Dave32265 | 02/11/09
"Have fun getting flash installed for it"?  AzuMao | 02/11/09
Thanks....  Dave32265 | 02/11/09
Flash???  GAXXIS | 02/12/09
Yep. By cheating.  frgough | 02/10/09
Irrelevant. Even if we're to believe your spin it doesn't change...  ye | 02/10/09
No cheating, but good try.  rtk | 02/10/09
You still haven't hacked Linux yet, rtk...  hasta la Vista, bah-bie | 02/11/09
Please  rtk | 02/11/09
C'mon, rtk...  hasta la Vista, bah-bie | 02/11/09
What exactly  rtk | 02/11/09
Compared to windows  AzuMao | 02/11/09
Azu, you'll never get the shills to admit that  hasta la Vista, bah-bie | 02/11/09
I didn't mean  AzuMao | 02/11/09
I realize that  hasta la Vista, bah-bie | 02/11/09
re: I realize that  rtk | 02/11/09
Believe your lies  hasta la Vista, bah-bie | 02/11/09
Not my lies.  rtk | 02/11/09
Stop embarrasing yourself  hasta la Vista, bah-bie | 02/11/09
lol  rtk | 02/11/09
Nonsense, and here's why...  hasta la Vista, bah-bie | 02/12/09
Cluebat  rtk | 02/12/09
Evading the point  hasta la Vista, bah-bie | 02/12/09
Good point  Cayble | 02/10/09
MS and IE the worst  z-max | 02/10/09
apple fanbois  GAXXIS | 02/10/09
Windows Fanbois  systemx | 02/10/09
Hmmmm....  MGP2 | 02/10/09
RE: Hmmmm....  beepa | 02/11/09
Your in the right Place  GAXXIS | 02/12/09
Right  AzuMao | 02/11/09
Better to have the patch as Apple learned at PWN2OWN  NonZealot | 02/10/09
Hang on to that OS X fail.  kozmcrae | 02/10/09
Why? Is OS X's market share decreasing? (nt)  ye | 02/10/09
Thanks to Vista and the stupid company that made it.  kozmcrae | 02/10/09
I don't believe that number.  ye | 02/11/09
I believe you've right this time.  kozmcrae | 02/11/09
Didn't we just see OS X  rtk | 02/10/09
Yes.  kozmcrae | 02/10/09
I'm sure the patches will go fine as always.  Cayble | 02/10/09
LOL! One "word" for you: PWN2OWN  ye | 02/10/09
If it's a non-issue...  msalzberg | 02/10/09
It wasn't rated critical in WU on my Vista system.  ye | 02/10/09
You didn't read the article you're posting about, then.  msalzberg | 02/10/09
I clearly said:  ye | 02/10/09
And it's clearly rated as...  msalzberg | 02/10/09
@msalzberg: I really don't care if you believe me or not.  ye | 02/10/09
@ye...  msalzberg | 02/10/09
Yup, protected mode will prevent exploits  honeymonster | 02/10/09
@msalzberg: If you'd bother to become informed instead of ignorant you'd...  ye | 02/11/09
@ye..  msalzberg | 02/11/09
Bad link  GAXXIS | 02/12/09
Riiiiight...  Kid Icarus-21097050858087920245213802267493 | 02/10/09
The one exploit isn't the point  Michael Kelly | 02/10/09
Well they hang onto it like  Kid Icarus-21097050858087920245213802267493 | 02/10/09
Pretty much the only apologists here  AzuMao | 02/11/09
SO  GAXXIS | 02/12/09
I'll tell them they need to be more careful when...  ye | 02/10/09
Uh, I was careful  Kid Icarus-21097050858087920245213802267493 | 02/10/09
Which virus did you get?  ye | 02/10/09
Compare what you wrote to what the OP wrote  NonZealot | 02/10/09
Yes, OP's staement was rabid  Kid Icarus-21097050858087920245213802267493 | 02/10/09
Question for NZ...  MGP2 | 02/10/09
OP = Original Poster  NonZealot | 02/10/09
Ah, got it.  MGP2 | 02/10/09
small correction  rtk | 02/10/09
I didn't elaborate but it was a year old vulnerability  NonZealot | 02/10/09
Pssst. Don't tell OS X users about this  honeymonster | 02/11/09
One word for him?  kozmcrae | 02/10/09
In an effort to see which could be the bigger fool...  ye | 02/11/09
I'm not surprised I missed your point.  kozmcrae | 02/11/09
So true  honeymonster | 02/11/09
Is that a word or a name?  James Quinn | 02/11/09
Well, actually no, Apple is the worst  honeymonster | 02/10/09
Reboot was automatic  Chad_z | 02/11/09
Oh please let this go! It's been debunked many times over.  ye | 02/11/09
Debunked by MSFT marketing?  Chad_z | 02/11/09
RE: Microsoft: ?Consistent exploit code likely? for IE vulnerabilities  DadsDrive | 02/10/09
Sniff, sniff...  MGP2 | 02/10/09
Hows this for ya!  xtrmgamr | 03/06/09
I'm tired of playing the...  RS9 | 02/10/09
Dino Dai Zovi tells MacWorld...  mechBgon | 02/10/09
Careful there. Someone may accuse you of beating a dead horse. (nt)  ye | 02/10/09
You forgot to mention...  914four | 02/10/09
Well, you can always ask him yourself...  mechBgon | 02/10/09
I agree  notsofast | 02/10/09
But OS X is still the most vulnerable OS - 3x more vulns than Vista  honeymonster | 02/10/09
So where are the attacks?  hasta la Vista, bah-bie | 02/11/09
Ah, so you didn't read the report then?  honeymonster | 02/11/09
I wanna see some bona-fide attacks...  hasta la Vista, bah-bie | 02/11/09
New Hardware?  notsofast | 02/10/09
A bit sensational...  PB_z | 02/10/09
Consistent exploit code likely? for IE vulnerabilities  aybloc | 02/10/09
RE: Microsoft: ?Consistent exploit code likely? for IE vulnerabilities  aybloc | 02/10/09
It looked so nice...  MGP2 | 02/10/09
Standard practice...  914four | 02/10/09
every patch comes with doom or gloom attach  Randalllind | 02/10/09
Re: every patch comes with doom or gloom attach  Cyrorm | 02/10/09
And then we could sue  honeymonster | 02/10/09
So where are the attacks?  hasta la Vista, bah-bie | 02/11/09
You need  Qbt | 02/11/09
So true  honeymonster | 02/11/09
Sorry, don't buy it...  hasta la Vista, bah-bie | 02/11/09
Come back  rtk | 02/11/09
Documented attacks, rtk...  hasta la Vista, bah-bie | 02/11/09
So,  rtk | 02/11/09
No proof, shill  hasta la Vista, bah-bie | 02/11/09
Apparently you're mathmatically challenged...  rx7racer | 02/11/09
RE: Microsoft: ???Consistent exploit code likely??? for IE vulnerabilities  donkeyhoetay | 02/10/09
You'll be writing your own OS then?  NonZealot | 02/10/09
Apparently jasonp has.  ye | 02/11/09
Then you will NOT like this:  honeymonster | 02/10/09
RE: Microsoft: ?Consistent exploit code likely? for IE vulnerabilities  gennx30 | 02/11/09
Confused?  honeymonster | 02/11/09
Neutering gennx30 -- Security By Obscurity  PMC-CON | 02/11/09
Uh huh, yeah right...  hasta la Vista, bah-bie | 02/11/09
LOL  rtk | 02/11/09
You still haven't referenced anything  hasta la Vista, bah-bie | 02/12/09
How exactly  rtk | 02/12/09
Doh...  hasta la Vista, bah-bie | 02/12/09
Right  AzuMao | 02/11/09
RE: Microsoft: Consistent exploit code likely for IE vulnerabilities  lynne1462@... | 02/11/09
Firefox has "run-code" vulnerabilities monthly....  dunn@... | 02/11/09
Because it's not how many that matters  AzuMao | 02/11/09
No doubt  hasta la Vista, bah-bie | 02/11/09
All software and operating systems require patching ...  JonathonDoe | 02/11/09
Yet we have to go through this circus every month  honeymonster | 02/11/09
Gotcha!  joe.smetona@... | 02/12/09
I Have a Reasonable Question, No Flame War Please!  QueenMama | 02/11/09
Because  AzuMao | 02/11/09
Since you asked nicely  NonZealot | 02/11/09
Webkit  vilppuu@... | 02/12/09
IE and Windows OS relationship  Thunderbird650 | 02/12/09
Thanks! But...  QueenMama | 02/12/09
Windows and browsers  oregonnerd13 | 02/13/09
RE: Microsoft: ?Consistent exploit code likely? for IE vulnerabilities  xtrmgamr | 03/06/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here