BleepingComputer.com: New DLL Vulnerability Exploited in the Wild

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

New DLL Vulnerability Exploited in the Wild

#1 User is offline   KarstenHansen 

  • The Dane
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Senior
  • Posts: 1,079
  • Joined: 06-June 09
  • Gender:Male
  • Location:Denmark

Posted 26 August 2010 - 04:07 AM

Quote

Over the weekend, Microsoft issued a new security advisory which covered a vulnerability in how Windows handles DLL files. The attack scenario would go this way: a vulnerable application would be used to open a file.

TrendMicro blog

Good info, enjoy
Karsten

This post has been edited by KarstenHansen: 26 August 2010 - 04:08 AM

With High Regards,
KarstenHansen,

Enjoy EVERYDAY of your life to the fullest, it can be over so so quick. Removing Malware is just like a good game of CHESS.

#2 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,514
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 02 September 2010 - 05:30 PM

An update on the DLL-preloading remote attack vector

Quote

Last week, we released Security Advisory 2269637 notifying customers of a publicly disclosed remote attack vector to a class of vulnerabilities affecting applications that load dynamic-link libraries (DLL’s) in an insecure manner. At that time, we also released a tool to help protect systems by disallowing unsafe DLL-loading behavior.

Today we wanted to provide an update by answering several questions we have received from customers and addressing common misperceptions about the risk posed by this class of vulnerability...

We have received several questions regarding the best way to enable the protection tool released on the Microsoft Download Center last week.

First, you should know that downloading and installing the tool alone will not protect a workstation from vulnerable applications. It ships “off-by-default” and must be enabled either system-wide or for specific applications. After releasing this tool, we received a number of questions on how best to deploy it. We have now updated the KB article to address them. We encourage you to review the updated knowledge base article 2264107...

Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users