Feeds

Microsoft sics worldwide braintrust on XP vuln

PDF attack prompts round-the-clock patch fest

Internet Security Threat Report 2014

Escalating attacks exploiting a serious weakness in PDF files have prompted Microsoft to issue an all-hands-on-deck call to fix a vulnerability that lurks in the bowels of Windows XP.

"We currently have teams worldwide who are working around the clock to develop an update of appropriate quality for broad distribution," Bill Sisk, a member of Microsoft's security response team wrote in a blog post Thursday. "Because ShellExecute is a core part of Windows, our development and testing teams are taking extra care to minimize application compatibility issues."

In the meantime, users should take extra care when receiving email attachments, even when delivered from known sources, and when visiting familiar or unknown websites, Sisk said. He didn't mention updates Adobe has issued here for its Reader program or here, but installing them immediately is also critical.

Sisk's warning is being prompted by a flurry of spam-carrying rigged PDF files that exploit the vulnerability. Based on reports by independent researchers, the emails appear to be on the rise. According to Ken Dunham, director of global response for iSIGHT Partners, one source of his intercepted more than 75,000 hostile PDF attachments in the past few days, a rate that translates to one sample every 10 seconds.

"Multiple private sources are now reporting a high volume of emails containing hostile PDF attachments," Dunham wrote in an email.

F-Secure is also reporting malware-tainted PDF are "being spammed heavily through email."

The urgency and transparency Microsoft is showing is commendable. But let's not forget that for more than three months, Redmond's security pros maintained that weaknesses resulting when third-party applications passed malicious uniform resource identifiers (URIs) to Internet Explorer was "not a vulnerability in a Microsoft product." As such, Redmond maintained, responsibility for plugging the hole lay elsewhere.

Two weeks ago, the software juggernaut, (which, incidentally, stunned Wall Street yesterday with strong quarterly earnings, largely on the sale of desktop titles) reversed itself on this position, admitting for the first time that the URI-handling weakness was an issue that had to be addressed by Microsoft.

The change of heart came as it became increasingly clear that the URI-handling weakness was doomed to repeat itself over and over on countless third-party apps. As Sisk put it, "...these third party updates do not resolve the vulnerability - they just close an attack vector."

Microsoft isn't due to issue another patch batch until November 13. ®

Beginner's guide to SSL certificates

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Internet Security Threat Report 2014
An overview and analysis of the year in global threat activity: identify, analyze, and provide commentary on emerging trends in the dynamic threat landscape.