Home > Security News > New threats target Microsoft apps
Security News:
EMAIL THIS

New threats target Microsoft apps

By Bill Brenner, Senior News Writer
26 Jun 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

IT professionals have two Microsoft threats to worry about as they start the new week.

First, Microsoft is warning those who haven't deployed a patch for flaws in the Remote Access Connection Manager (RASMAN) to do so immediately. Detailed exploit code is circulating, and attackers could use it to target the flaws.

Secondly, Cupertino, Calif.-based antivirus giant Symantec Corp. is warning of new proof-of-concept code that targets a security hole in Microsoft Windows Live Messenger, the instant messaging client formerly called MSN Messenger.

Microsoft released an advisory for the first threat Friday night, saying it targets a pair of critical remote code-execution flaws affecting versions of Windows 2000, XP and Server 2003. The RASMAN flaws could enable someone with malicious intent to take control of an affected system. Microsoft issued a patch for this problem in its MS06-025 security bulletin June 13.

"Microsoft is aware that detailed exploit code has been published on the Internet for the vulnerability addressed by Microsoft security bulletin MS06-025," a Microsoft spokesman said by email. He said the company is not currently aware of any active attacks based on this exploit code, but it is monitoring the situation closely. "Our investigation of this exploit code has verified that it does not affect users who have installed the update detailed in MS06-025 on their computers."

Symantec sent an advisory on the Windows Live Messenger issue to customers of its DeepSight Threat Management System Monday morning, saying version 8.0 is reportedly prone to a heap overflow vulnerability when processing malformed contact lists.

"This issue arises because the application fails to perform boundary checks prior to copying user-supplied data into sensitive process buffers," Symantec said. "The vulnerability presents itself when the application processes a malicious contact list (.ctt) file."

An attacker could craft a malicious contact list that supplies excessive data to the application through a large string value, such as a contact name, thus triggering the overflow condition. "This issue may lead to memory corruption," Symantec said. "An attacker may also leverage this issue to execute arbitrary code on a computer with the privileges of an affected user. Exploitation attempts may result in crashing the application as well."

While Symantec is not aware of any active exploits targeting the flaw, it confirmed that a proof-of-concept .ctt file is available. To mitigate the threat, Symantec recommended IT professionals take some of the following measures:

  • Run all software as a non-privileged user with minimal access rights.

  • Deploy network intrusion detection systems to monitor network traffic for malicious activity.

  • Do not accept or execute files from untrusted or unknown sources.

  • Avoid accepting and importing .ctt files that originate from users of questionable integrity.

  • Do not accept communications that originate from unknown or untrusted sources.

  • Implement multiple redundant layers of security.

    Tags: IM Security Issues, Risks and ToolsWeb Application SecuritySecurity Patch ManagementVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    IM Security Issues, Risks and Tools
    What are effective ways to stop instant messaging (IM) spam?
    Secure messaging complications result in limited protection
    Is it possible to ban chat programs on an enterprise LAN?
    How to lock down instant messaging in the enterprise
    AOL closes AIM attack vector, but risks remain
    Researcher says AIM still vulnerable, AOL insists it's fixed
    Serious security flaw in AOL Instant Messenger
    Security flaws found in AOL, Yahoo IM programs
    Flaw found in MSN Messenger
    AOL, Yahoo, Trillian IM applications under threat

    Web Application Security
    Black box and white box testing: Which is best?
    InZero Systems launches hardware-based security gateway
    Web application vulnerability assessment shows patching progress
    Preventing SQL injection attacks: A network admin's perspective
    Cisco acquires SaaS security vendor ScanSafe
    Web application firewall use goes beyond compliance, company finds
    Gumblar Trojan drive-by exploits spike following Adobe update
    Some Facebook applications lead to Russian attack sites
    Barracuda acquires Purewire expanding Web security reach
    An enterprise strategy for Web application security threats

    Security Patch Management
    What patch management metrics does Project Quant use?
    Squad: Tokenization, Phishing and the Feds
    Should management processes change based on a patch release schedule?
    Should Windows Mobile updates come from Microsoft?
    Adobe updates ColdFusion, JRun, Flex
    Trusteer CEO criticizes Adobe, touts better patch deployments
    Patch management study shows IT taking significant risks
    Vulnerability mitigation study shows need for faster patching
    Microsoft to issue security report card, new tool at Black Hat
    How to manage patches for Adobe

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    greynet  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts