9 ms·
Microsoft Warns of Zero-Day Under Attack
- kogir 13y agoTIFF is a great example of how a terrible specification can lead to endless security vulnerabilities in parsers. http://secunia.com/advisories/search/?adv_search=1&s=1&search=TIFF&vuln_title=1&vuln_bodytext=1&critical%5B%5D=0&impact%5B%5D=1&where%5B%5D=1 http://secunia.com/advisories/search/?adv_search=1&s=1&searc...
- voltagex_ 13y agoIs this the same class of exploits that affected image drawing on Windows a while back? (GDI?)
- EvanAnderson 13y agoI think you're talking about the MS06-001 vulnerability (http://technet.microsoft.com/en-us/security/bulletin/ms06-001 http://technet.microsoft.com/en-us/security/bulletin/ms06-00...) with Windows Metafile (WMF) files. This is a bug in the parser for TIFF files that allows for arbitrary code execution. MS06-001 was based on removing a "feature" of the WMF format (SETABORTPROC) that allowed for arbitrary code execution for legitimate, albeit antiquated, reasons.
- aroch 13y agoI have fond memories of the old PSP hacking scene and working on TIFF based exploits with DarkAlex, Booster and a couple others. It was really my first exposure to "hacking" and was fantastic
- tanzam75 13y ago> TIFF is a great example of how a terrible specification can lead to endless security vulnerabilities in parsers. TIFF is an Adobe spec, and we all know how great Adobe is at security ... Actually, TIFF predates Adobe involvement. It was inherited by Adobe when it bought Aldus. The file format was designed in 1986 and last revised in 1992. That's 21 years without an update -- an eternity in the computer world. Ironically, TIFF used to be known as "Aldus-Microsoft TIFF." Aldus designed the format, and Microsoft provided the marketing muscle to establish it as a de facto standard.
- ringmaster 13y agoIs it just me, or should this title be "Zero-Day Attack"? What's the "Under" all about?
- Groxx 13y agoPhrasing is a little weird, but I read it as that this is a zero-day that is actively being exploited, but a patch is not coming for a while. Supporting evidence for this interpretation: http://blogs.technet.com/b/msrc/archive/2013/11/05/microsoft-releases-security-advisory-2896666-v2.aspx http://blogs.technet.com/b/msrc/archive/2013/11/05/microsoft... which includes "We are aware of targeted attacks, largely in the Middle East and South Asia."
- eli 13y agoThey mean that it is being exploited in the wild, not just theoretically.
- cma 13y agoWhy not image decoding done in a sandbox?
- Groxx 13y agoSpeed, I'd imagine. But that should probably be revisited with the amount of exploits it seems to cause :/
- kevingadd 13y agoGDI is an incredibly old API that predates anything resembling modern sandboxing, so that's probably the only reason - they just never updated it to apply more security measures to image decoders.
- javajosh 13y agoThe original source is quite informative: http://technet.microsoft.com/en-us/security/advisory/2896666 http://technet.microsoft.com/en-us/security/advisory/2896666 It's a GDI component reading TIFF files exploit, it is being used in the wild right now, and the vuln won't be patched until Dec.
- mbrownnyc 13y agoHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Gdiplus REG_DWORD: DisableTIFFCodec 1 And... another reason to deploy EMET.
- ladzoppelin 13y agoOnly Vista and 2008 are affected by this exploit.
- yuhong 13y agoUnless you are using Office or Lync which have their own copy of GDI+. Office 2010 only uses their own copy when running under XP though unlike older versions and 2013 don't support XP at all so they don't have their own copy anymore.
- tanzam75 13y ago> Office 2010 only uses their own copy when running under XP though unlike older versions and 2013 don't support XP at all so they don't have their own copy anymore. That explains why Office 2013 isn't vulnerable. That, plus the fact that it uses DirectWrite instead of GDI. But then, why is Office 2010 vulnerable? It was released after Windows 7, which isn't vulnerable. Did it ship outdated libraries?
- onethree 13y agothe security alert i got this morning says otherwise: The following Microsoft products are vulnerable: Windows operating system: Windows Vista SP 2, Windows Vista x64 Edition SP 2, Windows Server 2008 for 32-bit Systems SP 2, Windows Server 2008 for x64-based Systems SP 2, Windows Server 2008 for Itanium-based Systems SP 2, Windows Server 2008 for 32-bit Systems SP 2 (Server Core installation), Windows Server 2008 for x64-based Systems SP 2 (Server Core installation) Microsoft Office suites and software: Microsoft Office 2003 SP 3, Microsoft Office 2007 SP 3, Microsoft Office 2010 SP 1 (32-bit editions), Microsoft Office 2010 SP 2 (32-bit editions), Microsoft Office 2010 SP 1 (64-bit editions), Microsoft Office 2010 SP 2 (64-bit editions), Microsoft Office Compatibility Pack SP 3 Microsoft communication platforms and software: Microsoft Lync 2010 (32-bit), Microsoft Lync 2010 (64-bit), Microsoft Lync 2010 Attendee, Microsoft Lync 2013 (32-bit), Microsoft Lync Basic 2013 (32-bit), Microsoft Lync 2013 (64-bit), Microsoft Lync Basic 2013 (64-bit)
- GioM 13y agoThe article is a little unclear - do I have to open a word doc, or is a TIFF embedded in a web page itself enough to cause infection? This may not be the place, but I could really use an opinion right now... I'm running firefox with noscript on Win7/64 and have Word 2007 installed on the system. I hit a suspect page last night, noscript blocked a number of objects, and at no point did I open a word doc, but... it was a link masquerading as am imgur link, that bounced me off at least two redirects (one of which was a .ir domain) before landing me on a spammy-looking blog. So, I guess the question is, how paranoid should I be? MSE, malwarebytes, and GMER all show nothing (as one would expect if it was a zero-day), but going full scorched earth and doing a system wipe on both my drives would be a huge inconvenience right now. I feel like wiping the whole damn thing on principle, but you can't wipe everything every single time you get spooked. PS: I did some testing, and it doesn't appear that firefox can display a tif file - it prompts for an external program (photoshop, in my case) and there's no application defined for the content type tiff in the firefox preferences. Opinions appreciated. Thanks in advance.
- FiloSottile 13y agoI think that a random spammy site is not going to afford burning such a zero-day. There is much lower-hanging fruit for them, and your system does not look like their target "difficulty level". That said with a level of paranoia like yours (that I'm not critiquing) I'm not really sure Windows is the best choice first of all.
- tanzam75 13y ago> I'm running firefox with noscript on Win7/64 and have Word 2007 installed on the system. ... at no point did I open a word doc ... So, I guess the question is, how paranoid should I be? Security advisory 2896666 covers only Windows Vista and Server 2008. Since you were browsing on Windows 7, you are not affected. It further states that you can be attacked if you open an email or file. You say that you did not open any Word documents. That's a start. But did you open any files at all in Microsoft Office? Outlook emails, Excel spreadsheets, Powerpoint presentations, etc.? If not, then you are not affected. At least, you're not affected by the current version of the attack.