Another update on the 0day Explorer exploit

Well, it looks like quite a bit took place while I was out on the “zero day exploit front”. It looks as though there is another update at The Sans Institute. The first thing to notice is that they’ve raised their alert level to Yellow over the impending active exploitation of this vulnerability.

Earlier updates on this event on my site are here and the initial post here.

Among the other information that Sans gives this evening is that they’ve tidied their summary from earlier. Essentially this exploit will open a remote shell and allow arbitrary code to be executed at the privilige level of the user. As of 4PM this afternoon Microsoft has announced an advisory on this issue, no patch yet. They are “aggressively investigating” these reports of the vulnerability.

Sans still has their patch available (Follow the above link to find the details.) They do note that this patch may break Activex components that try to activate this dll library. The dll in question of course, is msdds.dll a dotnet (.NET) component and ships with several products. (See earlier post here or the Sans institutes for more details there.)

Microsoft, in their advisory is “concerned” over how this vulnerability was disclosed saying that the practice of notifying the vendor first should have been the way to deal with the issue. (All malicious hackers out there remember when you find a new vulnerability, tell MS first before you start using it.) Realistically, most of the time this is what is done by the responsible IT Security professionals. In this case I notice that the SANS Institute also has an open letter to Microsoft.

The summary of that is that this vulnerability may be zero day, but the underlying problem has been known for 380 days and Microsoft has YET to address the issue. (They point to this information week article as evidence of a similar flaw. It appears that Microsoft has urged users to set “kill bits” on individual Activex/Com objescts and have a write up on how-to in their knowledge base, essentially open regedit and burrow to some really NASTY looking keys and change a dword.

(The key is named by the CLSID of the Activex control, their suggestion for determining the correct CLSID is to uninstall all of them and only reinstall the one you are trying to modify.)
I would hesitate with this myself, I can’t imagine recommending this to ANYONE as a fix for them to try. Ultimately SANS gets at the real problem which is the default policy is to ALLOW the kind of communication that causes this exploit. They also call on MS to change to a default DENY policy and that the issue needs attention and CANNOT wait until Vista and(or) IE7.

There is a workaround suggested at SANS it sounds like it may take a bit to work through and I would not suggest this for someone that’s never used regedit before. Apparently this Knowledge Base article gives more information.

Further there are a few more updates at Security Fix on this afternoons events. They mention both the SANS yellow alert and the Microsoft announcement.

Hopefully we’ll see an out of cycle Microsoft Patch that will take care of this and any other future problems exploiting this ActiveX flaw.

Related Posts

Blog Traffic Exchange Related Posts
  • Big Go-Daddy hosting attack In what feels like a continuation of recent bad news related to major hacks and data losses.....George Ou reports on a BIG hack of GoDaddy hosting customers. There was also a big hack-athon by Turkish hackers over the last week that will be recorded as the biggest mass-web-site-defacement on record.........
  • Exploit for Unpatched Internet Explorer vulnerability Well.... buckle your seatbelts it's going to be a bumpy start to the week. the securityfix as well as are reporting on exploit code that has been released that takes advantage of an unpatched Internet Explorer vulnerability. According to the Sans institute diary entry... they have tested the exploit......
  • Microsoft's priorities... I didn't really think of this in context, but George Ou points out that Microsoft issued an "out of cycle" patch for their DRM software in response to the FairUse4WM software that stripped DRM protections from Windows Media Files. It took a mere 3 days from being made aware of......
Blog Traffic Exchange Related Websites
  • Twitter Mouse-Over Flaw Send Users to Dangerous Links On Tuesday morning September 21, 2010, was hacked in a very crafty way.  Twitter users needed to only move their mouse cursor over links on their twitter page to be redirected without the user intervention or permission.  When redirected, they would be sent to malicious and offensive destinations,......
  • San Mateo County Hike in Pillar Point Location: This trail is located at Pillar Point in San Mateo County as part of the San Mateo County Harbor District The Hike: This is a 1.2 mile walk out and back that begins at the outskirts of the Princeton Harbor and ends at the beach. Distance: This is......
  • Microsoft Security Bulletin Summary for September 2010 - Issued: September 14, 2010 ******************************************************************** Microsoft Security Bulletin Summary for September 2010 Issued: September 14, 2010 ******************************************************************** This bulletin summary lists security bulletins released for September 2010. The full version of the Microsoft Security Bulletin Summary for September 2010 can be found at With the release of the bulletins for September 2010, this......    Send article as PDF   

Similar Posts

See what happened this day in history from either BBC Wikipedia
Amazon Logo

Comments are closed.

Switch to our mobile site