ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Microsoft finally fixes Pwn2Own browser flaw

By | June 8, 2010, 12:12pm PDT

Summary: The Microsoft Patch Tuesday train rolled into town today, dropping off a massive 10 security bulletins with fixes for at least 34 documented vulnerabilities.

The Microsoft Patch Tuesday train rolled into town today, dropping off a massive 10 security bulletins with fixes for at least 34 documented vulnerabilities.

Three of the bulletins are rated “critical” because of the risk of remote code execution attacks.  Affected products include the Windows operating system, Microsoft Office, the Internet Explorer browser and Internet Information Services (IIS).

This month’s patch batch also provides cover for a known cross-site scripting flaw in the Microsoft SharePoint Server and a publicly discussed data leakage hole in Internet Explorer.

Microsoft is urging its users to pay special attention to MS10-033  (Windows), MS10-034 (ActiveX killbits) and MS10-035 (Internet Explorer) because these contain fixes for issues that may be exploited by malicious hackers very soon.

Here’s the skinny on these three bulletins:

  • MS10-033 — This security update resolves two privately reported vulnerabilities in Microsoft Windows. These vulnerabilities could allow remote code execution if a user opens a specially crafted media file or receives specially crafted streaming content from a Web site or any application that delivers Web content. This is rated Critical for Quartz.dll (DirectShow) on Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008; Critical for Windows Media Format Runtime on Microsoft Windows 2000, Windows XP, and Windows Server 2003; Critical for Asycfilt.dll (COM component) on Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2; and Important for Windows Media Encoder 9 x86 and x64 on Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.
  • MS10-034 — This security update addresses two privately reported vulnerabilities for Microsoft software. This security update is rated Critical for all supported editions of Microsoft Windows 2000, Windows XP, Windows Vista, and Windows 7, and Moderate for all supported editions of Windows Server 2003, Windows Server2008, and Windows Server 2008 R2.  The vulnerabilities could allow remote code execution if a user views a specially crafted Web page that instantiates a specific ActiveX control with Internet Explorer. It also includes kill bits for four third-party ActiveX controls.
  • MS10-035 — Fixes five privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.This security update is rated Critical for Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4; Critical for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on Windows clients; and Moderate for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on Windows servers.

Qualys CTO Wolfgang Kandek noticed that four of the 10 bulletins address zero-day issues, the most significant being MS10-035, which fixes the zero-day published by Core Security for an information disclosure vulnerability originally published in February 2010.

It also fixes the Pwn2Own vulnerability that security researcher Peter Vreugdenhil used to win ZDI’S competition at CanSecWest.  During that contest, Vreugdenhil bypassed all built-in protections such as DEP and ASLR by combining multiple flaws and attack methods.

The MS10-040 bulletin is also interesting.  It covers a a remotely exploitable vulnerability in all versions of IIS, but it is present only if the administrator has downloaded and installed the Channel Binding Update and enabled Windows Authentication. It further requires an account on the system, reducing the number of vulnerable hosts to a small subset.  Microsoft rates this an “important” update.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

59
Comments

Join the conversation!

Just In

dough rounder
dough rounder 11th Dec
I'd be very grateful if you could elaborate a little bit further. Appreciate it!
Hello there! I know this is kind of off topic but I was wondering if you knew where I could get a captcha plugin for my comment form? I'm using the same blog platform as yours and I'm having difficulty finding one? Thanks a lot!
When I originally commented I clicked the "Notify me when new comments are added" checkbox and now each time a comment is added I get four emails with the same comment. Is there any way you can remove me from that service? Appreciate it!
Hello there! This is my first visit to your blog! http://www.chinacateringequipment.com
0 Votes
+ -
Safari on OS X
Trolleur Updated - 8th Jun 2010
I'm glad I use Safari on OS X, I'm immune to such flaws!

I feel sorry for the Windows users who approach every Patch Tuesday with immense fear and trembling!
0 Votes
+ -
Likewise
NonZealot 8th Jun 2010
@Trolleur
I'm glad I use Chrome on Windows, I'm immune to all of these flaws:
http://www.zdnet.com/blog/security/apple-plugs-48-safari-webkit-security-holes/6623?tag=content;search-results-rivers

PS There were 48 flaws in Safari ALONE, only 34 flaws in all of Windows and associated bits COMBINED. happy
0 Votes
+ -
RE: Microsoft finally fixes Pwn2Own browser flaw
Patrick Aupperle 9th Jun 2010
@NonZealot Lol, number of patched flaws != number of flaws.
Just because someone refuses to patch security holes does not mean they don't exist. Your logic makes no sense. By your logic, you should switch to Windows 95, it has no flaws (or at least patches for flaws) recently.

I guess I am not sure about the number of flaws, and you may be right that mac has more, I just wanted to point out that patches != flaws. Also, no I am not a Mac user.
0 Votes
+ -
@NonZealot To refresh youe memory (if there be one) Chrome is very vulnerable to ANY attack
@NonZealot

Microsoft does not patch security bugs what it has find in its internally tests. It only patch security bugs what are found by third party. Microsoft keeps all security bugs in secret as long as it can and fix them then in next service pack, behind the curtains. This way Microsoft gets better "open bug summaries".

Example, Microsoft know 7 months the security bug what was used against Google. IT DID NOT FIX IT FOR 7 MONTHS!

And again few months ago Microsoft was caucht (not the first time) for patching security bugs what it did not inform in kb at all.

The IT-admins can not know at all what patch fix what. They need to install all patches because Microsoft can patch stuff behind curtains. And among long time experiences IT-admins is well know that when Microsoft release Service Pack, it can fix on it few hundred security and other bugs. Service Pack is not just a package of all patches released to that time and few new features. It is Microsoft's package of secret patches. And no one can notice anything clearly from it because it is so big and touch so many files in the software system.
0 Votes
+ -
@NonZealot Thanks for sharing. i really appreciate it that you shared with us such a informative post..
Assignments Dissertations Essay Writing
@NonZealot The difference between the right word and the almost right word is really a large matter ??? it's the difference between a lightning bug and the lightning.
Logo Design Pros Logo Design Pros
Thank you so much for informing us about somethign like this "Qualys CTO Wolfgang Kandek noticed that four of the 10 bulletins address zero-day issues, the most significant being MS10-035, which fixes the zero-day published by Core Security for an information disclosure vulnerability originally published in February 2010." keep it up...

Renter Background Check
0 Votes
+ -
@Trolleur if you are immune to such silliness why did Apple plug 48 Safari web kit holes. must have just been user interface improvements
0 Votes
+ -
i'm glad u dont think there are exploits for unix. Even glad'r u most likely dont know you are running unix.
ignorance is why virus stay healthy and abundant.
and yes IE and MS os are major security holes, but to think you are protected is absurd....
0 Votes
+ -
I lol at you
D2 Ultima 8th Jun 2010
@Trolleur
I think your name denotes what you actually are. A troll. If you feel that Macs are immune to viruses... ha. ha. ha. I'll remind you that the winner of one of those who-can-hack-the-computers-the-fastest contests like CanSecWest hacked the Mac in 1 second. Simply drive by download and he took full control of the Mac. Using Safari.
It's people like you that make me *want* to learn how to hack Macs, just so I can make you all eat your words >_>.

And if you find a Windows user that approaches every Patch Tuesday with immense fear and trembling, let me know; because I know no one like that. Either the people don't care and updates automatically happen, or, like me, they know what they're doing and Patch Tuesdays are more of a formality and an annoyance that we must restart our PCs than any substantial thing.
0 Votes
+ -
1 second???
i8thecat 8th Jun 2010
@D2 Ultima

Get a clue D2... You can't hack anything in 1 second....

I would actually love to see some idiot write a real virus for OSX... That person would be public enemy number 1 among the hacker community. They would quickly learn the real meaning of pain... Mac OS X is a certified UNIX OS... Fully compliant... Any idiot who writes a virus that can affect OSX has just written a virus that can attack any flavor of UNIX...

Hackers run UNIX... Not Win-Blows...

Are you starting to understand why there hasn't been a real virus written for OSX???

Only malware... Socially engineered malware... None of which is a real virus... Malware that some idiots refer to as trojans, but renaming an install package, does not a trojan make...

Hacking and writing/coding virii are two entirely different things... Confusing the two makes you look like a moron.
0 Votes
+ -
I wish I still had the link
D2 Ultima 8th Jun 2010
@i8thecat
Oh please. I might be exaggerating 1 second, but he finished it the fastest and got to keep the macbook pro he took complete remote control over. The mac was the fastest hacked OS in the competition; faster than Windows XP. Also, someone that can hack Mac OS X will not be the public enemy number 1. You're giving Macs too much credit. Nobody cares about Macs on a large scale; which is why people don't actively write viruses for them. And if Macs had this great "UNIX certification" which meant they cannot write a virus for it, then why does apple keep updating and plugging security holes, and why are Antivirus software being written for Mac OSes? Just because people do not use it, doesn't mean that there's never a need for it. Large corporations running Macs wouldn't be caught dead without a working Antivirus if their IT staff was worth their salt. And yes I know there are large corporations that use Macs. I'm not that stupid to think Windows is 100% large scale use.
@D2 Ultima
i8thecat is correct. It wasn't 1 second. It was done in under 20 seconds.. still faster hacked than any other platform. And it took another 20 seconds for them to lift the SMS database off of an iphone on top of that.
@D2 Ultima "the real meaning of Pain"? "Public enemy number 1"?

You've got a wildly distorted view of the security landscape.
0 Votes
+ -
@SoYouSaid

*yeah
*we're
@Trolleur
Lets not forget the 800mb patch apple released the week after pwn2own. 800mb.
0 Votes
+ -
@Trolleur Yes, but are you immune to Apple's wonkiness? I feel sorry for people who don't know how to use a grown-up computer!
0 Votes
+ -
@Shiggity

I'm hoping you're talking about Linux. Otherwise, you're talking about the machine that advertised itself fairly recently with little kids at the keyboard.

Not exactly grown up, now is it?
0 Votes
+ -
@Shiggity

I'm hoping you're talking about Linux. Otherwise, you're talking about the machine that advertised itself fairly recently with little kids at the keyboard.

Not exactly grown up, now is it?
0 Votes
+ -
@Trolleur --Hmmm Safari si safe==Neber throw stones while living in a glass house my friend LOL
ahh you're so glam ! 3 replica watches
0 Votes
+ -
Is Safari that good? I wanna find out from an daily user. I use Windows for several year and I'm not completly satisfied with it. http://www.handyortungkostenlos.eu/Prepaid-Handy-Orten | http://www.handyortungkostenlos.eu/Handyortung-gratis
0 Votes
+ -
IE is the safest browser out.
ashdude 8th Jun 2010
IE is safe because Charlie Miller doesn't write exploits for it. I sleep better at night knowing this.
0 Votes
+ -
Browser and O/S troll wars get old
e_caroline@... Updated - 8th Jun 2010
It gets real old watching some overly proud newbies get all fired up trolling on about the only O/S or browser they have figured out how to operate.

In about every case it is some foolish newbie who has ascended all the way to "novice" in their skillset and so is ever-so-proud of their trivial accomplishment.

They are almost always too lazy or inept to learn more than one and so try to "put down' all others so they can feel incredibly clever though they are just diaper-wearing pants-peeing newbies.
@e_caroline@... shush now! With the current state of the economy, we need to keep the diaper manufacturers in business! Long live diaper wearing trolls!!!

Besides, consultants like me also need them to run their systems on blind faith and ignorance. If systems don't break, I'd be out of business.
0 Votes
+ -
@e_caroline@...
It's like watching 9y/o kids argue over which football team is the best, all passion & venom, no knowledge or experience.
0 Votes
+ -
@e_caroline@...

Yikes! and I was JUST about to declare my affiliation...
0 Votes
+ -
Well Said...
smtp4me@... 9th Jun 2010
@e_caroline@... Very well said. I have worked with: IBM System 3090 mainframes and AS400's, DEC VAX 11-785 minis, MS-DOS, every version of Windows, several flavors of Linux and Unix, and even OSx.

I love these people who buy an Apple computer because they see a commercial on TV proclaiming how secure they are - and then sit back with a false sense of security and even superiority over the users of other operating systems. They read about viruses, trojans, and malware and proclaim themselves security experts when in reality they couldn't explain an advanced security concept if their life depended on it.

None of them could give an accurate description of the difference between NAT and PAT on a firewall, or memory injection, or SYN attacks, or....
0 Votes
+ -
Most significant vulnerability
adytsecc 8th Jun 2010
"most significant being MS10-035, which fixes the zero-day published by Core Security for an information disclosure" ?Sorry? where is the reference to Core Security in MS10-035. Clearly the most serious is pwn2own.
0 Votes
+ -
Ryan you are a clown
roblung 8th Jun 2010
ryan I can see you always overhyping some company """research""" or products. please don't do it ! it is tooo obvious. Is funny how now you put on Core competitor (Qualys) mouth your core security advertisement! haha good work
Ah well, time to install Sun OS or some out of the way legecy server that no one knows about happy
0 Votes
+ -
I have a question. Sometimes when I play video I might not need to be watching. I get blue screen of death, saying Bad Pool request or Bad Pool Dump. Is that 1 of these flaws? It always happens when I'm using MS media player and skipping thru movies. Thanks
0 Votes
+ -
They named it B. P.

It's all blown out and full of holes!!!
0 Votes
+ -
Why can Microsoft write real explanations such as Ryan's rather than MS Babblespeak boilerplate?
0 Votes
+ -
Thank the lawyers
Vesicant Updated - 10th Jun 2010
@ptcruiser70663
0 Votes
+ -
Missing the point?
Diminshon 9th Jun 2010
Here's a thought, how about making the application/OS vendors write better code to start with, before releasing to the general public. When did this trend of using the general public for beta testing catch on ? Adobe are shocking for the quality of the code that comes out that place. Just look at the issues for FLash and Acrobat, and this after somehow establishing Flash and PDF as de-facto standards.
0 Votes
+ -
Yaaawwwn ...
phil8192 9th Jun 2010
I run browser "X" on operating system "Y", both of which are obscure and in a tiny minority. Security through obscurity -- not worth the effort of hackers to target.
0 Votes
+ -
Anyone who thinks their operating system or browser (or any software for that matter) has no flaws, I have some land to sell you 100 miles west of Hawaii! The major yardstick is how fast they fix their flaws, that is where MS fails big!
0 Votes
+ -
The Pwn2Own exploit only dates from March 2010. That hardly justifies the "finally" in your headline. ZDNet is such a crock. The only reason I'm here is to watch the train wreck.
0 Votes
+ -
lol
mikroland 10th Jun 2010
@Vesicant
0 Votes
+ -
Take the Apple/Linux is superior to MS posts and just ignore them. Personally, I think if you buy a Mac it proves you like to overpay for appliances. I know people who have Ipads and now don't know what to do with them, but they had to have it because its from apple and therefore cool. I tell people save their money and buy a netbook. Yes, we get it, there are exploitable things in MS's code. That has nothing to do with everyone else's crappy code that no one is really using.
0 Votes
+ -
It never fails to amaze me just how many ways there are to remotely execute code on Windows via the IE APIs. Around five years ago, before we sacked Windows completely, we had a box acquire a botnet rootkit via another screwy security-free api in IE. As it turns out it was a new exploit at the time.

How little things have changed. An architecturally flawed piece requires continuous fixing but apparently can never be repaired. I'm glad we left Windows to the slow learners.
0 Votes
+ -
Can Apple release an update that'll patch up the smug from OS X users? That would be nice.
This is an excellent article. The following publish supplies genuinely high quality info. My spouse and i?meters bound to check in it. Truly extremely helpful points are given listed here. Many thanks a great deal. Carry on favorable functions. vintage snapback hats best solid state drive
This is a really good read for me. Must admit that you are one of the best bloggers I have ever read. Thanks for posting this informative article. baby gifts for boys baby gifts for girls
I like the article you wrote here; it is very informative and useful for the internet users like me. I will come back to read more blog posts on your website and I have bookmarked your website as well Thank You know style clothing store girls clothing stores online
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
0 Votes
+ -
dough rounder
dough rounder 11th Dec
I'd be very grateful if you could elaborate a little bit further. Appreciate it!
Hello there! I know this is kind of off topic but I was wondering if you knew where I could get a captcha plugin for my comment form? I'm using the same blog platform as yours and I'm having difficulty finding one? Thanks a lot!
When I originally commented I clicked the "Notify me when new comments are added" checkbox and now each time a comment is added I get four emails with the same comment. Is there any way you can remove me from that service? Appreciate it!
Hello there! This is my first visit to your blog! http://www.chinacateringequipment.com

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix