On MovieTome: The 10 worst movies of 2009 so far!
BNET Business Network:
BNET
TechRepublic
ZDNet

October 31st, 2007

Macrovision patches patch-delivery tool, leaves DRM zero-day wide open

Posted by Ryan Naraine @ 1:36 pm

Categories: Botnets, Browsers, Data theft, Digital rights management, Exploit code, Hackers, McAfee, Metasploit, Open source, Patch Watch, Pen testing, Privacy, Responsible disclosure, Rootkits, Spam and Phishing, Spyware and Adware, Symantec, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Digital-rights Management, Macrovision Corp., Patch Management, Tool, Digital Rights Management (DRM), Microsoft Windows, Patches, Digital Media, Security, Operating Systems

In Focus » See more posts on: DRM

Macrovision patches patch-delivery tool, leaves DRM zero-day wide openMacrovision today released a patch for a very severe vulnerability in the FLEXnet Connect (InstallShield) patch-delivery offering but there’s still no word on a fix for a zero-day attack vector in the company’s Safedisc DRM application.

FLEXnet Connect, which lets users electronically deliver applications, patches, updates, and messages directly to third-party systems, has been updated to correct an ActiveX issue that could lead to code execution attacks.

[ SEE: Zero-day flaw in Macrovision DRM app under attack ]

A warning from iDefense spells out the risk scenario:

Exploitation allows attackers to execute arbitrary code with the privileges of the currently logged-in user. In order for exploitation to occur, users would be required to have a vulnerable version of the software installed and be lured to a malicious site. Even though the update control does display an interface, no additional interaction is required in order for exploitation to occur.

Since this control is marked “safe for scripting”, it can be launched from a web page without warning dialogs. While it is possible for an alert user to determine what is occurring and cancel the installation, the window of opportunity is small and based solely upon the time required for the system to complete the download.

Macrovision InstallShield Update Service versions 5.01.100.47363 and 6.0.100.60146 are confirmed vulnerable . Previous versions are also suspected to be at risk, iDefense said.

Patches are available for download at Macrovision’s FLEXnet Connect site.

Macrovision patches patch-delivery tool, leaves DRM zero-day wide openMeanwhile, Windows users are still waiting for a known — and under attack — flaw affecting the Macrovision Safedisc (secdrv.sys) DRM scheme.

That vulnerability, which affects default installations of Windows XP and Windows 2003, can be exploited to overwrite arbitrary kernel memory and execute arbitrary code with SYSTEM privileges.

Proof-of-concept exploit code (.zip file) for the Safedisc issue is already in circulation. A functional exploit is commercially available through the CORE IMPACT and Immunity Canvas penetration testing platforms.

There is a strong likelihood that the Macromedia Safedisc patch will be bundled with Microsoft’s updates on Patch Tuesday next month (November 13, 2007).

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 3 Talkback(s)
Macro-patch...... Micro-patch
What's the difference? It's all a
crap-patch. (Read the rest)
Posted by: Ole Man Posted on: 10/31/07 You are currently: a Guest | | Terms of Use
Sue the parasite  Mectron | 10/31/07
You made a *slight under-estimate*  thx-1138_@... | 10/31/07
Macro-patch...... Micro-patch  Ole Man | 10/31/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline