Feeds

IE code execution bug can bite older Windows

Surf, press F1, get pwned

Remote control for virtualized desktops

Microsoft's security team is investigating a security vulnerability in older versions of Windows that allows attackers to execute malware on end user machines.

The bug combines scripts based on Microsoft's Visual Basic language with Windows help files for Internet Explorer. It makes it possible for an attacker hosting a malicious website to remotely run arbitrary code by convincing the user to press the computer's F1 key in response to a popup window.

The vulnerability doesn't threaten users of Windows 7, Windows Server 2008, and Windows Vista, Microsoft's Jerry Bryant wrote here, and so far, there are no reports of attacks that exploit the weakness.

The attack was described on Friday by Maurycy Prodeus of iSec Security Research. The vulnerability is the result of the passing a samba share as a helpfile parameter, he said. The researcher also warned there is a stack based buffer overflow in the winhelp32.exe file when parameters are too long.

Microsoft plans to issue guidance once its investigation is completed, Bryant said. ®

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Seattle children’s accelerates Citrix login times by 500% with cross-tier insight
Seattle Children’s is a leading research hospital with a large and growing Citrix XenDesktop deployment. See how they used ExtraHop to accelerate launch times.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Managing SSL certificates with ease
The lack of operational efficiencies and compliance pitfalls associated with poor SSL certificate management, and how the right SSL certificate management tool can help.