On Metacritic: BioShock 2: How does it compare?
BNET Business Network:
BNET
TechRepublic
ZDNet

November 12th, 2009

Microsoft bracing for malware attacks from embedded fonts

Posted by Ryan Naraine @ 11:16 am

Categories: Arbitrary Code Execution, Botnets, Browsers, Denial of Service (DoS), Exploit code, Metasploit, Microsoft, Passwords, Patch Watch, Responsible disclosure, Spam and Phishing, Spyware and Adware

Tags: Malware, Microsoft Internet Explorer, Microsoft Corp., Attack Vector, Font, Attack, Metasploit, Microsoft Windows, Security, Operating Systems

Heads up to all Microsoft Windows users: If you’re running Windows 2000, Windows XP or Windows Server 2003, stop what you’re doing and immediately download and apply the MS09-065 update released earlier this week.

Security researchers say it’s only a matter of time — days not weeks — before malicious hackers start exploiting one of the vulnerabilities via booby-trapped Web pages or Office (Word or PowerPoint) documents.

The specific vulnerability — in the font parsing subsystem of the win32.sys driver — provides an entry point for hackers to take complete control of an unpatched machine without any user action beyond normal browsing or opening a rigged document file.

A proof-of-concept exploit has already been fitted into the Metasploit point-and-click tool.  According to Metasploit’s HD Moore, the code triggers a BSoD (blue screen of death) from a Web page.  With some modifications, Moore expects to get reliable code execution very soon.

Microsoft’s MS09-065 bulletin says an exploit was already publicly available before the update was ready on Patch Tuesday (perhaps this one released since August?), meaning that malware authors have gotten a long head start researching entry points for attacks.

Metasploit’s Moore said it was “a pretty easy bug” to find based on the description provided by Microsoft.

“This demonstrates how just plain wrong some features of Windows are,” he added.

According Brian Cavenah, a researcher in Microsoft’s security response team, the company expects to see reliable exploit code publicly available within 30 days.

On the SR&D blog, Cavenah outlines the severity of this issue:

The severity rating of critical was chosen since the vulnerable code is exposed through Internet Explorer and can be exercised without user interaction/notification.

Here are the worst-case attack vectors that result in remote code execution without authentication:

  • Malicious fonts (TTF’s) delivered within .eot files hosted on malicious web sites which are rendered in all versions of Internet Explorer by default.
  • Malicious office documents e-mailed to victims with social engineering to entice the victim to open the document which contains a malformed embedded font which would then be rendered upon opening the Office document (PowerPoint and Word documents are the most likely attack vectors).

There are also some local attack vectors (worst case scenario is Local Elevation of Privilege):

  • Malicious fonts (TTF’s) delivered to win32k.sys by an authenticated user in a multi-user environment (Terminal Services (TS)) scenario. Such scenarios might abuse AddFontResource() to achieve this.

The best protection from likely attacks is for all affected users to download and apply the patch.

Alternatively, affected Windows uers can disable support for parsing/loading embedded fonts in Internet Explorer (warning: Web sites which make use of embedded font technology will not render properly).

This can be done via IE’s Tools > Internet Options > Security settings:

* Images via Microsoft’s SR&D blog and the Wikipedia entry for Embedded OpenType Font.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 148 Talkback(s)
Ha Ha I have a Tin Hat.
I have my tin hat on! O mighty tin hat protect this pathetic Microsoft servant of IT from evil. And hurry up and apply that patch eh?... (Read the rest)
Posted by: Altotus Posted on: 11/18/09 You are currently: a Guest | | Terms of Use
Not too worried here......  daMan25 | 11/12/09
You should have blocked the power outlet too...  The Mentalist | 11/12/09
No Glass around here  linux_kernel | 11/12/09
Windows are important...  Ceridan | 11/12/09
Wrong.....  daMan25 | 11/12/09
Right  AzuMao | 11/13/09
You should have blocked the power outlet too.  gertruded | 11/12/09
Not enough  AzuMao | 11/13/09
Is anyone surprised?  The Mentalist | 11/12/09
Not at all -3. I knew you'd show up and start trolling.  James T. Kirk | 11/12/09
Nobody is surprised  Duke E. Love | 11/12/09
Bugs and Holes  medezark@... | 11/13/09
Holes and bugs...  vulpine@... | 11/13/09
According to Wikipedia there are...  ye | 11/13/09
Oh Ye of the tired old argument about "marketshare"  whisperycat | 11/13/09
I know you're tired of the truth.  ye | 11/13/09
Windows Lite  1djk1 | 11/13/09
Well Said  WebDavCrisp | 11/13/09
Netscape?  Duke E. Love | 11/13/09
Boot leg PC's that can't get patched?  Duke E. Love | 11/13/09
Conficker infections were not equally distributed geographically  NonZealot | 11/13/09
Not only is ye blind, but so is NonZealot. Not surprised.  vulpine@... | 11/13/09
How dare you!  AzuMao | 11/13/09
Ya.. bugs do happen.. which is why there is this thing called  AzuMao | 11/13/09
Even QA cannot find every single bug  Lerianis10 | 11/16/09
It's not a matter of finding every single little bug.  AzuMao | 11/16/09
That's what SDL is all about.  Lester Young | 11/16/09
No, not with a 1.2 billion installed base  Qbt | 11/12/09
You forgot the qualifier  AzuMao | 11/16/09
One word.  Lester Young | 11/16/09
Botnets made up of a bunch of dialup users from China  AzuMao | 11/17/09
No. After all, this is Windows. What else to expect?  AzuMao | 11/13/09
Message has been deleted.  Linux Geek | 11/12/09
I'm covered too  NonZealot | 11/12/09
False... almost  Ceridan | 11/12/09
Windows 7 is listed as not affected  Earthling2 | 11/12/09
Oops my bad [NT]  Ceridan | 11/12/09
Major correction;  AzuMao | 11/13/09
Same here...  Ceridan | 11/12/09
But is it protected from tomorrow's exploit too?  The Mentalist | 11/12/09
Yes.  Ceridan | 11/12/09
Try Windows 7 with.....  daMan25 | 11/12/09
...  Ceridan | 11/12/09
So?  AzuMao | 11/13/09
It is fixed.. after it's been known by hackers for a long time!  AzuMao | 11/13/09
Message has been deleted.  Tom12Tom | 11/12/09
"Windoze" is windows with a French accent...  The Mentalist | 11/12/09
Actually....  Ceridan | 11/12/09
Interesting...  linux_kernel | 11/12/09
Remember...  Ceridan | 11/12/09
That same thought can be applied to  AdventTech67 | 11/12/09
I am aware  Ceridan | 11/12/09
Yes. He have a problem that occures very often.  AzuMao | 11/13/09
I'm covered, too!  Grayson Peddie | 11/12/09
iptables ~ netfilter is industrial strength...  linux_kernel | 11/12/09
You could do the same with Windows too.  ye | 11/12/09
Routers are Linux derived NOT Windows♠  Use_More_OIL_NOW | 11/12/09
I'm getting it from the fact that it can be used as a router.  ye | 11/13/09
You can use Internet Connection Sharing for that but it's very limited.  Grayson Peddie | 11/13/09
Are you ******* RETARDED?????  AzuMao | 11/13/09
Quit with your namecalling. wink  Grayson Peddie | 11/13/09
Then quit citing GRC and pretending you're somehow protected.  AzuMao | 11/14/09
Go ahead. Try to hack into my Linux server.  Grayson Peddie | 11/16/09
Did you read the article?  AzuMao | 11/16/09
@AzuMao, It's a reply to Linux Geek.  Grayson Peddie | 11/16/09
Oops. My bad then, sorry.  AzuMao | 11/17/09
It's okay.  Grayson Peddie | 11/17/09
I wish he hadn't deleted his post.  AzuMao | 11/17/09
It's pretty much the moderators that deleted his post.  Grayson Peddie | 11/18/09
Again with the fear mongering?  NonZealot | 11/12/09
I agree with you...  Ceridan | 11/12/09
Patch today or forever hold your peace  Ryan NaraineZDNet Moderator | 11/12/09
Old unpatched versions of Windows are under attack  Earthling2 | 11/12/09
Or, in other words, use default Update settings  NonZealot | 11/12/09
We can't all...  Ryan NaraineZDNet Moderator | 11/12/09
Much better to deal with a malware infestation then patch.  ye | 11/12/09
Quite true... I personally have NEVER  Lerianis10 | 11/12/09
You try ...  Ryan NaraineZDNet Moderator | 11/12/09
You try...  eqpc | 11/12/09
Perhaps you missed the following in my post:  ye | 11/12/09
No point talking to some MS zealots  deaf_e_kate | 11/12/09
@deaf_e_kate: Let me ask you this:  ye | 11/13/09
@poo: A Linux patch killed my video once  NonZealot | 11/13/09
Second that, NZ  Lester Young | 11/16/09
Then those computers shouldn't be connected to the internet  Lerianis10 | 11/12/09
Windows computers shouldn't be turned on, period.  AdventTech67 | 11/13/09
You've just answered your own question  NonZealot | 11/13/09
Because most people don't have problem with them  Lerianis10 | 11/16/09
Because they're idiots.  AzuMao | 11/16/09
Yes they did.  AzuMao | 11/13/09
yet another reason to use Vista  directory | 11/12/09
Close, but not quite there.  The Mentalist | 11/12/09
Elevation on Vista; Windows 7 is unaffected  Earthling2 | 11/12/09
Earth to directory, this isn't the only vulnerability in the world.  AzuMao | 11/13/09
RE: Microsoft bracing for malware attacks from embedded fonts  Tola1005 | 11/12/09
RE: Microsoft bracing for malware attacks from embedded fonts  Loverock Davidson | 11/12/09
Sooner or later something is going to snap...  The Mentalist | 11/12/09
Empty threats, and he happens to be right  Lerianis10 | 11/12/09
Nope  AzuMao | 11/13/09
Yet  Viva la crank dodo | 11/12/09
Mind if I quote you on that?  vulpine@... | 11/13/09
re: Windows 7 is not affected...  linux_kernel | 11/12/09
There is a patch  Earthling2 | 11/12/09
RE: Microsoft bracing for malware attacks from embedded fonts  gertruded | 11/12/09
No Linux effected?  znetlol | 11/12/09
What a novel concept...  Ceridan | 11/13/09
And since most exploits are OS specific  AzuMao | 11/13/09
Ryan Naraine... You disgust me.  Duke E. Love | 11/12/09
Link? There should be a link to Windows Update in your start menu.  AzuMao | 11/13/09
Windows & IE & Explorer.exe  Use_More_OIL_NOW | 11/12/09
Keep trolling  tonymcs@... | 11/12/09
re: Keep trolling ????????????  Use_More_OIL_NOW | 11/12/09
Yup, keep trolling.  rtk | 11/13/09
Coming from rtk..  AzuMao | 11/13/09
Fail  AzuMao | 11/13/09
No valid points.  Lester Young | 11/16/09
Poorly understood by tonymcs maybe.  AzuMao | 11/17/09
Yet another Flame war sponsored by ZDNet  Duke E. Love | 11/12/09
Driven by the overrepresentation of fringe tech  tonymcs@... | 11/12/09
Desktop Linux is around 40% or greater ♠♠♠  Use_More_OIL_NOW | 11/12/09
40%? bahahah.  rtk | 11/13/09
You still believe those stats?  anothercanuck | 11/12/09
You forgot this one.  Lester Young | 11/16/09
You're right, there's no comparison between  AzuMao | 11/13/09
which run most of the Internet?  Duke E. Love | 11/13/09
The ones he listed.  AzuMao | 11/14/09
VS?  AzuMao | 11/13/09
UnFarkingBelievable  Duke E. Love | 11/13/09
There's not any room left for "rational discouse" when..  AzuMao | 11/14/09
NO! Who gets Pwned at "PWN2OWN" first  Lerianis10 | 11/16/09
LOL  AzuMao | 11/16/09
Windows BOTS help the economy! ???????  Use_More_OIL_NOW | 11/12/09
RE: Microsoft bracing for malware attacks from embedded fonts  anothercanuck | 11/12/09
Well it makes sense  AzuMao | 11/13/09
HAWW!!! I mean, HAWW!!!!  bendib | 11/12/09
malware from fonts...what a disaster  ljenux-23043766007667558234416105604265 | 11/12/09
How is that worse than malware from pictures, music, or video?  NonZealot | 11/13/09
Well...  Ceridan | 11/13/09
Explain Please.  vulpine@... | 11/13/09
Because when by pictures you mean executable files..  AzuMao | 11/13/09
Ye's addled thinking on "marketshare" exposed  whisperycat | 11/13/09
Can't you see a little problem?  Earthling2 | 11/13/09
How DARE you!?!?  AzuMao | 11/13/09
RE: Microsoft bracing for malware attacks from embedded fonts  Steveny Ballmer | 11/13/09
Lemme guess.. posted by a spam bot, running on.. a Windows box.  AzuMao | 11/13/09
It's like old times, man...  Grayson Peddie | 11/14/09
Continua Corecta!  bgrove777 | 11/14/09
Ha Ha I have a Tin Hat.  Altotus | 11/18/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here