New Exploit Could Affect Both Office 2007 and IE

By Scott M. Fulton, III | Published September 19, 2006, 9:03 PM

An exploit discovered yesterday by security consultancy Sunbelt and verified by Microsoft this afternoon involving the Vector Markup Language (VML) library in Windows could potentially affect not only users of Internet Explorer, but also of the current beta of Office 2007.

Like so many recently discovered vulnerabilities, this one too involves a twist on an old exploit that Microsoft may have thought it patched back in 2004. But this new VML buffer overrun may be of more critical importance now than two years ago, since VML is now a standard component of the Office Open XML format -- the default file format of the next edition of Microsoft Office.

Late yesterday, Sunbelt's vice president for research, Eric Sites, posted screenshots to his company's blog reportedly showing a malicious program failing to be detected by Microsoft's Baseline Security Analyzer, just prior to launching shellcode -- machine code routines invoked through the command prompt -- which Sites described as spyware.

In an interview with the Washington Post's Brian Krebs, Sites stated Sunbelt wasn't entirely certain yet what the alleged spyware would do.

This afternoon, Microsoft confirmed the problem, posting a new security advisory. While the advisory did not specifically list Internet Explorer, it did provide boilerplate text describing a Web-based attack scenario, where theoretically an attack could be launched using this exploit.

But Sunbelt's explanation of the exploit's discovery on one of its virtual systems did not state that Sunbelt knew it originated from Internet Explorer. Late today, Sunbelt's Sites told BetaNews he believed the VML library in question (VGX.DLL) was installed with Internet Explorer 5.0, though he wasn't certain. He said he would investigate the possibility of the Office 2007 beta being involved.

On one of our test systems where the Office 2007 beta is installed, the version of VGX.DLL registered there (6.0.2900.2180) was the same as on a Windows XP Professional SP2 system where only Office 2003 is installed. Word 2003 also uses VML for the current version of WordArt, a drop-in customizable graphics library.

So while VML isn't just for Web pages any more, the most recently trusted -- and patched -- version of the VML library appears to be the one installed with the operating system. This discounts the possibility that a later version of VGX.DLL, perhaps installed by a beta program, overwrote the existing patched version and re-introduced the 2004 vulnerability.

The problem there, however, is that a malware attack that exploits VML could do damage that extends beyond just the browser, but to Office and perhaps other applications as well. Further, it opens the possibility that the Web-based attack scenario posited by Microsoft may not be the only way the library is exploited.

When asked by BetaNews, Sunbelt engineers could not confirm that the malware they detected was derived from a Web-based attack. Although the VML library has no active code elements -- it doesn't execute commands, merely explain how graphics are rendered -- an Office document that does contain active elements could be delivered via e-mail. However, system policies for Outlook or Outlook Express may have to be relaxed. Sunbelt did not comment on that possibility today, probably pending further research.

The consultancy Internet Security Systems issued a report on a e-mail based VML exploit in May 2004. As of today, ISS' database suggests this problem has never been addressed, though it rates the risk level for this problem as "medium."

In its advisory today, Microsoft said it was aware that this newly discovered twist was being actively exploited, and that it has set a milestone date of October 10 to produce a patch. Sunbelt's Eric Sites suggested that users who may be suspicious of VML's behavior can easily disable it using the following command at the prompt: regsvr32 -u "%ProgramFiles%\CommonFiles\Microsoft Shared\VGX\vgx.dll"

Comments

View comments by with a score of at least

IE7 is NOT vulnerable because it has a new vgx.dll
Microsoft Vector Graphics Rendering(VML) file version 7.0.5700.6

Score: 0

|

"New Exploit Could Affect Both Office 2007 and IE"

Of course it will. Did you actually think Security is improving at redmond?

The complexity of Office and Windows is just introducing more vulns, not less. This is what we call a bad architecture.

We also won't be seeing new versions of the operating system within 6 years. You heard it here folks.

Score: 0

|

But due to limited-account usage gaining popularity and sandboxing YOURSELF concept (just cuz new vuls are bound to be discovered) will be used with Vista - I think we'll all do just fine...

Score: 0

|

OH SNAP! OH NO!

NOT ANOTHER VULNERABILITY!

...just another day in windoze world, LOL

Score: 0

|

Please correct the command - you are missing a critical space:
regsvr32 -u "%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll"

A space between Common and Files.

Score: 0

|

See here is the problem when a single company controls such a major portion of something. Flaws become a real head ache. It never goes away either, as stated here with it being patched in 2004. I am surprised they didn't say vista rc1 is also effected. I mean office 2007 should be built on this new secure code base right? So a 2004 vulnerability that was supposed to be patched also effects it? A product yet to be released in 2007? Only Microsoft could manage something like.

Just think this is who will be in charge of our security, exclusively in about 3 years from January 2007. Why is that you ask? Because just about every other security firm will be out of business. Mcafee, trendmicro and all the little pee wee's will be the first to go. All that will be left is symantec for the most part and they will be significantly weakened. they won't have a customer base, except maybe corporate firewalls based on Linux boxes.

Score: 0

|

corrected: Sunbelt's Eric Sites suggested that users who may be suspicious of Internet Explorer's behavior can easily disable it using the following command at the run/command prompt: firefox

Score: 0

|

Firefox which also had a security issue resolved by releasing 1.5.0.7
SO,,,ummm....IE is the only one with security errors?

Score: 0

|

Notice the word "resolved" in your post?

So did I.

Score: 0

|

Firefox 1.5.0.7 is still vulnerable to Michal Zalewski flaw

test here:
lcamtuf.coredump.cx/ffoxdie.html

Score: 0

|

dang worse one since that image flaw in january?

seriously, no offence (ok maybe a little), but i'd like to see a top 10 worse MS flaws type page.

Score: 0

|

How would you define "worst?"

- number of total unpatched?
- Severity of those unpatched. (i.e. system level access, wormable, passthrough firewalls, etc)
- Effect on global commerce or web traffic?
- least number of workarounds?

Score: 0

|

heh right, now it sounds like an award show, hmm

Score: 0

|

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.

Nokia re-affirms its commitment to Symbian, sort of

Maemo won't necessarily be replacing Symbian in the Nokia N-Series, but that's definitely a place where it will be found.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

Gartner: SMS-based money transfer will be bigger than mobile browsing, search

Gartner issues its predictions for the 10 things our phones will be doing in 2012.

Don't forget to upgrade to Firefox 3.6 beta 3 today

Mozilla has released the latest beta its Firefox 3.6 browser software, just over one week after beta 2.