Zero-Day Windows Shell Exploit Emerges
By Ed Oswald | Published September 29, 2006, 2:58 PM
Microsoft confirmed the existence Thursday of a vulnerability affecting the Windows Shell feature in Windows XP, 2000, and 2003. The issue exists in the WebViewFolderIcon ActiveX control, and successful exploitation could result in an attacker gaining the same user rights as a local user.
According the FrSIRT, the vulnerability was first discovered in mid-July, however exploit code did not surface until recently.
According to a security advisory, the vulnerability can be exploited through a specially crafted Web site that exploits the vulnerability. However, Microsoft said a user would have to be tricked into visiting the site.
Microsoft says that it is aware that proof of concept code is publicly available on the Internet, but knows of no attacks that attempted to take advantage of the flaw. "We will continue to investigate these public reports," it said.
Security firm Secunia has rated the issue as "extremely critical," and confirmed the existence of the issue on a fully patched version of Internet Explorer 6 and Windows XP SP2. It recommended users disable the "WebViewFolderIcon" ActiveX control, which Microsoft did as well.
"We are working on a security update currently scheduled for an October 10 release," Microsoft said.
The existence of so called "zero-day exploits," or code that is released on the same-day or before the exploit itself its publicly confirmed, on Microsoft products has increased with the advent of the Patch Tuesday program.
Some security firms have coined the term "Zero Day Wednesday" to describe the flood of exploits that seem to appear for critical Microsoft issues the day after the patches repair the problem.
The amount of zero-day exploits in existence highlight the need for IT administrators to stay on top and apply all applicable Patch Tuesday updates, security experts say.
If you are looking for a totally secure system you can turn off your computer. Otherwise, choose the browser you're most comfortable with, and use it.
This discussion seems both endless and pointless.
Score: 0
|You don't have to turn off your Windows machine to be secure, just unplug the network cable.
Score: 0
|Yawn...
Windows vulnerabilities are no longer news..its business as usual...the status quo
What is really funny is to listen to the various folks occupying high school cafeterias STILL debating it.
Move on folks...
Score: 0
|Isn't this the exploit that has been MASSIVELY spreading over Yahoo! Messenger for like several weeks now?
Score: 0
|Yahoo Messenger uses Web Folders with ActiveX? What the?
Score: 0
|Everybody should acknowledge that information about security issues are valuable. So - whatever browser you prefer or not is of no relevance for this info. And, maybe, you could even inform those, whom you are laughing about - those who need your knowledge. Come on, help your fellow human beings, even if you're doing it for the 1xxnd/th time!
Score: 0
|almost all of these vulnerabilities can be avoided if said person is not the type of person who calls and asks how to turn their pc on...most of these exploits are easily avoidable and are caused by user error granted the exploit is there but if you dont get tricked into downloading something or going somewhere you should not be this is not an issue
Score: 0
|IE7 is NOT vulnerable
Score: 0
|THIS time...
Score: 0
|Nor is any other major browser - they don't support ActiveX for a reason.
Score: 0
|Odd how I don't see a large article posted on the recent 0day OpenSSH vulnerability, though I suppose its only a dos and not a remote execute so its not as bad but you all know what I mean..
Score: 0
|tell me again how XP is the safest and most secure thing Microsft has ever made.
Score: 0
|Where have you been? XP is a ton more secure than it's been in the past, and a ton more secure than prior versions of Windows.
Just because it's not perfect yet (this is Microsoft after all) doesn't mean it's not the best ever.
What spurious logic behind that complaint.
Score: 0
|not perfect yet?
come on!
How many daily to weekly problems do we have to hear about?
I'm not seeing the most secure. I see more vulnerabilities being found in XP than has ever been found in any other OS. Many of them are actually created (as per Microsoft's own admissions) form their own so-called fixes.
Score: 0
|"tell me again how XP is the safest and most secure thing Microsft [sic] has ever made."
That's easy, it's because their previous OSs are even MORE unsecure. :)
Score: 0
|True, how many xp fixes repaired one problem and leave room for another problem to come up? I like the comment on the bottom of this page; it's best to use a browser, like firefox, that doesn't support ActiveX control.
Score: 0
|Windows 9x/ME..... nothing else to say
Score: 0
|Ever consider that times have changed in the last 8 years? The internet is more widely used in greater capacity than ever before - it goes without saying that security vunerabilities are found more readily today.
And I think you'll find if you go and install Windows 98 and update it, you find a similar number of patches to XPSP2 - and then you'll be missing 2-3 years of security upgrades.
XP is the most secure MS platform for home users. 9x code is not even in the race - it's a pre-Internet design.
Score: 0
|You qualification was "and update it"
If I were to install 98se, I would not update it.
Score: 0
|I could easily avoid most (not all, but most) problems by using an older os like 98se.
Score: 0
|Not really. Windows 95 and 98 are a cinch to break into.
Score: 0
|Cannon fodder.
Score: 0
|OH ZOIKS!
NOT ANOTHER ZERO DAY!
Too bad for you guys that run windoze...
Score: 0
|I run Windows, come get me.
Score: 0
|ditto, a careful balance of AV, browser etc & yre laffing :)
Score: 0
|BRING IT ON!!!!
Score: 0
|As usual, Opera and Firefox users are unaffected, as they don't support ActiveX for good reason..
Score: 0
|It's readily apparent that depending on a Microsoft infrastructure is becoming a losing battle.
Score: 0
|According to the most recent update to security-firm Symantec's biannual Internet Security Threat Report, the last six months saw a significant uptick in the number of security vulnerabilities found in web browsers. Leading the way was Firefox, with 47 flaws discovered. Researchers and hackers discovered 38 vulnerabilities in Internet Explorer, 12 in Safari, and seven in Opera.
Score: 0
|Not all flaws are equal. It's like doing a security survey and finding that bank A has a cracked skylight on the roof and bank B has a broken lock on the front door. Are they both equally insecure because they both have a security flaw? No. One flaw requires a cat burglar with a set of tools to get in, the other allows anybody to walk in off the street.
As well as the seriousness of the flaw, you would also have to consider how long they take to be fixed. If both banks have a broken lock on the front door, which bank is more secure, the one that fixes the lock as soon as somebody notices it's broken, or the bank that says, 'we'll fix the lock next month as part of out regular maintenance cycle, unless we notice a lot of people stealing from the bank in the meantime'?
On top of that, to push the analogy, you have to consider each bank's record. If bank A says, last year we had 47 security problems, including cracked windows and broken locks, and we fixed all of them in a timely fashion before any money was stolen, would you hold it against them?
What about bank B, which always says 'security problems? What security problems? What broken lock? Oh, that broken lock! What robbers making off with the cash? Oh, those robbers! Don't worry, it's only a very limited robbery. We'll get the lock fixed next month. Maybe.'
Score: 0
|Which is why I use Opera,the only browser with 0 unpatched vunrabiltiies, and a very low rate of discovered vunrabilities.
I you want safe browsing, Opera is the only choice.
Score: 0
|Hear! Hear! - - Well said, indeed.
Score: 0
|LOL, FireFox has a new 0 day exploit discovered, a very serious one...
Again proving, that if you want secure and functional browing, Opera is the ONLY choice.
It's an impressive feat on Opera's part, that their browser is available on so many platforms, and still maintains it's near faultless security record.
Score: 0
|Mark Gillespie said..."FireFox has a new 0 day exploit discovered, a very serious one"
-----------------------------------------------------
Potentially. It's not verified, and it's not
listed on any security sites as yet.
Leave your bias at the door and let the
actual facts play out as they may.
Score: 0
|