The Register® — Biting the hand that feeds IT

Feeds

Windows 0day allows malicious code execution

Potential 'nightmare'

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Antimalware provider Prevx has sounded the alarm about a serious vulnerability in fully patched versions of Microsoft Windows. It allows attackers to execute malware, even in versions designed to withstand such exploits.

Technical details have already been published on a Chinese forum, leading to speculation that it won't be long before attackers exploit it in the wild.

“This could potentially become a nightmare due to the nature of the flaw,” Prevx researcher Marco Giuliani wrote here. “We expect to see this exploit being actively used by malwares very soon – it's an opportunity that malware writers surely won't miss.”

The flaw resides in the win32k.sys part of the Windows kernel and results from an API known as NtGdiEnableEUDC that fails to properly vet user input for harmful content. Attackers can exploit the bug to redirect overwritten return memory addresses to malicious code, which is then executed with kernel mode privileges. As a result, the flaw allows even users or processes with limited privileges to execute code will elevated rights.

“Being a privilege escalation exploit, it bypasses by design even the protection given by the User Account Control technology implemented in Windows Vista and Windows 7,” Giuliani said. “All Windows XP/Vista/7 both 32 and 64 bit are vulnerable to this attack.”

Microsoft "is aware of the issue and it is under investigation," according to a statement, which a spokeswoman attributed to Jerry Bryant, Group Manager of the company's Response Communications.

On Wednesday evening, Microsoft Security Response tweeted: "We're investigating public PoC for a local EoP vuln requiring an account on the target system."

No further details were available at time of writing. If confirmed, the unpatched vulnerability would be the second known 0day to affect a widely used piece of Microsoft software. Earler this month, researchers unearthed an unrelated security bug in earlier versions of Internet Explorer that is being exploited on compromised websites. ® ®

This article was updated to include MSR's tweet.

Agentless Backup is Not a Myth

Kind of awesome

It's kind of awe inspiring just how many security flaws a large chunk of code can hold. You'd think we'd run out eventually, but it's like some sort of magic perpetual motion machine.

13
1

This is what you get

for bundling UI code in the kernel.

Repeat after me: I shall not incorporate UI/Shell/Explorer/other unneeded code in the kernel. Damn thing is hard enough to write securely as it is.

Tux, for getting this right from the start.

10
4

And in other news, the ocean is wet...

... and there is oxygen in the air, and there are chuck norris jokes in Barrens Chat in World of Warcraft. (Along with the cross roads being under attack)

4
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key
Microsoft borks botnet takedown in Citadel snafu
Stupid Redmond kicked over our honeypots, wail white hats