Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 10-27-2007, 05:13 AM
Symantec's Avatar
Symantec Symantec is offline
Senior Member
 
Join Date: Oct 2006
Posts: 295
Patch Tuesday/Exploit Wednesday?

Patch Tuesday/Exploit Wednesday?
<p>Today we had an interesting sample shared with us. It was a Microsoft Word document which, when opened, was simply crashing Word. We tried using various combinations of Word versions, patches and languages, and in each case (with the exception of Office 2007) opening the document would cause Word to crash. After taking a closer look, we could see that the document contained shell code and three other pieces of malware. What was interesting about the document was that it wasn't in OLE format, meaning that it wasn't a standard Microsoft Office document.</p>

<p>After some investigation we determined that the document had actually been created using Word for Macintosh. Here you can see the difference between the header in an OLE (Windows) format document compared to that of a Mac format document:</p>

<p><a href="http://www.symantec.com/enterprise/security_response/weblog/upload/2007/10/pic_lrg.html" onclick="window.open('http://www.symantec.com/enterprise/security_response/weblog/upload/2007/10/pic_lrg.html','popup','width=850,height=152,scroll bars=no,resizable=no,toolbar=no,directories=no,loc ation=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://www.symantec.com/enterprise/security_response/weblog/upload/2007/10/pic_sml.jpeg" width="370" height="66" /></a><br />
<strong>(Click for larger image)</strong></p>

<p>It was then that we had a "light bulb" moment, because we knew that just yesterday Microsoft had released a patch for a vulnerability in Word for Mac documents. (See <a href="http://www.microsoft.com/technet/security/Bulletin/MS07-060.mspx">Microsoft Security Bulletin MS07-060</a>.) Taking a closer look at that vulnerability, we confirmed that this document was in fact exploiting the same vulnerability.</p>

<p>It seems that the trend for exploiting vulnerabilities around the same time as Patch Tuesday continues. Microsoft themselves confirm in their advisory that they have seen this issue exploited in the wild. However, in our experience the exploitation of such vulnerabilities tends to be very targeted in nature. The good news is that the default configuration in Microsoft Office 2007 and Office 2003, Service Pack 3 will not allow you to open some older Office file formats, including Office for Macintosh documents (see <a href="http://support.microsoft.com/kb/922850">MS KB922850</a> for further details). We're continuing to investigate the behavior of the exploit on other Office versions.</p>

<p>Symantec Antivirus products will detect the malicious document as <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2007-101014-1321-99">Trojan.Mdropper.Z</a>. The dropped files are detected as Trojan.Dropper, Backdoor.Trojan and Hacktool.Rootkit.</p>

<p>Thanks to Elia Florio for the analysis!</p>
http://www.symantec.com/enterprise/security_response/weblog/2007/10/patch_tuesdayexploit_wednesday.html
http://www.symantec.com/enterprise/security_response/weblog/2007/10/patch_tuesdayexploit_wednesday.html
Wed, 10 Oct 2007 09:14:08 -0800
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump



    All times are GMT -5. The time now is 11:29 AM.


    Firefox 2