Exploit for "Zero-Day" Vulnerability Detected
Sat, 31 March 2007
Tettnang, 31 March 2007 - Avira warns about the spreading of modified .ani files. These files started to circulate yesterday and exploit a vulnerability in "Windows Animated Cursor Handling". Microsoft has published an Advisory, but no patch is available yet.
Apart from Microsoft Windows XP SP 2, the new operating system Windows Vista is also affected. The danger consists in the fact that the vulnerability is exploited in the background, without the user's knowledge. It usually downloads further malware from the Internet, in order to gain control on the computer.
On Thursday, March 29th, the first attempt for proof of concept was spotted. The next day, Avira Lab has obtained the first URLs hosting the modified .ani files. Up to this moment, more than 44 different files were detected on over a dozen servers.
The exploit code reminds us of an old vulnerability from January 2005: MSO05-002. The updated engine version 7.03.01.47 detects as EXP/MS05-002.Ani.A the .ani files containing the new exploit code.
The possible ways of infection are modified websites or emails. Avira recommends that you temporarily deactivate the preview of emails in HTML mode. Additionally, we advise administrators to block the following domains, because they were identified as hosting one or more modified files:
h t t p://1.520sb.cn
h t t p://220.71.76.189
h t t p://222.73.220.45
h t t p://55880.cn
h t t p://81.177.26.26
h t t p://85.255.113.4
h t t p://a.2007ip.com
h t t p://bc0.cn
h t t p://count12.51yes.com
h t t p://count3.51yes.com
h t t p://d.77276.com
h t t p://fdghewrtewrtyrew.biz
h t t p://i5460.net
h t t p://jdnx.movie721.cn
h t t p://macr.microfsot.com
h t t p://newasp.com.cn
h t t p://ppp.aaa.jtdns.com
h t t p://s103.cnzz.com
h t t p://s113.cnzz.com
h t t p://stattrader.biz
h t t p://ttr.vod3369.cn
h t t p://uniq-soft.com
h t t p://web73304914.web.128web.com
h t t p://wsfgfdgrtyhgfd.net
h t t p://www.04080.com
h t t p://www.33577.cn
h t t p://www.h3210.com
h t t p://www.hackings.cn
h t t p://www.i5460.net
h t t p://www.jonnyasp.com
h t t p://www.khgames.co.kr
h t t p://www.koreacms.co.kr
h t t p://www.macrcmedia.com
h t t p://www.macrcmedia.net
h t t p://www.ncph.net
h t t p://www.xxx.cn
h t t p://ym52099.512j.com
h t t p://61.153.247.75
h t t p://61.153.247.76
h t t p://e.attrezzi.biz
h t t p://pc.uz3z.com
h t t p://if.iloveck.com
Please note that the blank spaces were inserted for security reasons.
| Other news from this category |
Archive |
 |
 |