On mySimon: North Face Elkhorn 0 Degree Sleeping Bag
BNET Business Network:
BNET
TechRepublic
ZDNet

April 14th, 2009

Microsoft ships fixes for Excel, WordPad malware attacks

Posted by Ryan Naraine @ 10:52 am

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Complex Attacks, Data theft, Exploit code, Hackers, Microsoft, Passwords, Patch Watch, Responsible disclosure, Spyware and Adware, Windows Vista, Zero-day attacks

Tags: Vulnerability, Microsoft Internet Explorer, Microsoft Corp., Security, Ryan Naraine

Microsoft’s April batch of security patches are out:  8 bulletins with patches for at least 20 documented vulnerabilities.

The most serious of the flaws could lead to remote code execution attacks that give a malicious hacker complete ownership of a vulnerable machine.  This month’s fixes cover several code execution bugs that are currently being actively exploited (Microsoft Excel and Microsoft WordPad) and two issues that have been publicly known for at least a year (token kidnapping and Safari-to-Internet Explorer blended threat).

[ SEE: One-year-old (unpatched) Windows 'token kidnapping' under attack ]

At first glance, Windows users should treat the cumulative Internet Explorer update (MS09-014) as a high-priority fix because of the increased threat from Web-borne attacks. It covers:

  • Four privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer or if a user connects to an attacker’s server by way of the HTTP protocol. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

The raw details, via Microsoft’s SWI team:

Bulletin Highest bulletin severity Highest Exploitability Index Rating Any vulns known to be public-known? Attack vector for code execution / Notes
MS09-009 Critical High (1) Yes, CVE-2009-0238 known to be exploited already. XLS file attached to email or posted on a website. These vulnerabilities are critical only on Office 2000. Other versions of Office force user to click through a prompt, reducing severity to Important.
MS09-010 Critical High (1) Yes, CVE-2009-0235 known to be being exploited already. RTF, WRI, or DOC file attached to email or posted on a website. Blog entry with more details about Converter Attack Surface here.
MS09-013 Critical High (1) Yes, exploit tools are publicly available for CVE-2009-0550 (SMBRelay). However, this CVE is Important, not Critical. The attack vector for the Critical CVE is a client-side application uses WinHTTP to generate a network-based request to a malicious server. The malicious server responds with a malformed request causing either a client-side application crash or code execution in the context of the user running the application. Internet Explorer does not use WinHTTP.
MS09-014 Critical High (1) Yes, CVE-2008-2540 is known externally. However, it is rated “Moderate”. This bulletin also addresses a portion of CVE-2009-0550, mentioned above. The attack vector for the Critical CVEs would be Internet Explorer connecting to a malicious website.

You can read more about how we fixed the public CVE-2008-2540 (Safari Carpet Bombing) here.

MS09-011 Critical Medium (2) No. AVI file attached to email or webpage pointing you at an AVI file.
MS09-012 Important High (1) Yes, exploit tool publicly available. After an attacker compromises an IIS-hosted web application, they could use these vulnerabilities to escalate to SYSTEM.  You can read more about how we fixed this vulnerability here.
MS09-016 Important Low (3) Yes, limited details of this vulnerability are known externally No threat of code execution.
MS09-015 Moderate High (1) Yes. No known attack vector.

More to come…

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 44 Talkback(s)
RE: MS Patch Tuesday: 8 bulletins, 20 vulnerabilities
Can't knock them for aggressively at least attempting to correct vulnerabilities; especially with transparency. I have been doing research on This* digital security site.... (Read the rest)
Posted by: Steve KTG Posted on: 04/19/09 You are currently: a Guest | | Terms of Use
yet another reason to use Vista  qmlscycrajg | 04/14/09
Yet another reason to use Linux...  techboy_z | 04/14/09
Open Office and Firefox don't work in Windows?  NonZealot | 04/14/09
The individual programs are....  todbran@... | 04/16/09
Linux?  honeymonster | 04/14/09
But less exploits  914four | 04/15/09
Using 1 metric to measure security is silly  SpikeyMike | 04/15/09
Story is an opinion piece from 2004  honeymonster | 04/15/09
RE: MS Patch Tuesday: 8 bulletins, 20 vulnerabilities  Loverock Davidson | 04/14/09
Applauding Microsoft?  sombertattoo | 04/14/09
Show me ...  de-void | 04/14/09
Show me....  njnb | 04/14/09
Show me...  nikacat | 04/15/09
Well said  betelgeuse68 | 04/14/09
LOL!  eMJayy | 04/14/09
Corrected download link  dgust@... | 04/15/09
nice wee fiction...  zkiwi | 04/14/09
No  honeymonster | 04/14/09
Your position is debunked soundly here:  SpikeyMike | 04/15/09
An opinion piece from 2004  honeymonster | 04/15/09
They deserve it!  Loverock Davidson | 04/14/09
Avoiding holes in the first place  honeymonster | 04/14/09
Least amount of disclosed holes  eMJayy | 04/14/09
So you are  honeymonster | 04/14/09
Were this the case...  jasonp@... | 04/15/09
Actually yes  914four | 04/15/09
Linux code is closed to...  Erroneous | 04/15/09
Thank you Lovey  914four | 04/15/09
Good for Microsoft!  trm1945 | 04/15/09
Almost forgot  eMJayy | 04/14/09
On Linux?  honeymonster | 04/14/09
How is that possible?  Marty R. Milette | 04/14/09
Hooked on phonics...  jasonp@... | 04/15/09
At least I know Linux is safer  eMJayy | 04/15/09
Kidding yourself  honeymonster | 04/15/09
Honeymonster must be......  todbran@... | 04/16/09
You don't have to  914four | 04/15/09
RE: MS Patch Tuesday: 8 bulletins, 20 vulnerabilities  pdx-man | 04/15/09
I really don't....  Erroneous | 04/15/09
You are free to switch  honeymonster | 04/15/09
Re; any other operating system with less patches?  hkommedal | 04/16/09
Not much interest in BSD  honeymonster | 04/16/09
You gotta be Lovie's little bro......  todbran@... | 04/16/09
RE: MS Patch Tuesday: 8 bulletins, 20 vulnerabilities  Steve KTG | 04/19/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More