ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Microsoft issues temporary 'fix-it' for Duqu zero-day

By | November 4, 2011, 8:14am PDT

Summary: The vulnerability affects the Win32k TrueType font parsing engine and allows hackers to run arbitrary code in kernel mode

Microsoft has shipped an advisory to formally confirm the zero-day vulnerability used in the Duqu malware attack and is offering a temporary “fix-it” workaround to help Windows users block future attacks.

The vulnerability affects the Win32k TrueType font parsing engine and allows hackers to run arbitrary code in kernel mode, Microsoft said in its security advisory.

The company also confirmed my earlier report that this vulnerability will NOT be patched as part of this month’s Patch Tuesday bulletins.

The advisory includes a pre-patch workaround that can be applied to any Windows system.

follow Ryan Naraine on twitter

To make it easy for customers to install, Microsoft released a fix-it that will allow one-click installation of the workaround and an easy way for enterprises to deploy. The one-click workaround can be found at the bottom of this KB article.

Microsoft explained that the Duqu malware exploit targets a problem in one of the T2EMBED.DLL, which called by the TrueType font parsing engine in certain circumstances.  The workaround effectively denies access to T2EMBED.DLL, causing the exploit to fail.

Windows kernel 'zero-day' found in Duqu attack ]

From the Microsoft Security Response Center blog:

To further protect customers, we provided our partners in the Microsoft Active Protections Program (MAPP) detailed information on how to build detection for their security products. This means that within hours, anti-malware firms will roll out new signatures that detect and block attempts to exploit this vulnerability. Therefore we encourage customers to ensure their antivirus software is up-to-date.

Additionally, our engineering teams determined the root cause of this vulnerability, and we are working to produce a high-quality security update to address it. At this time, we plan to release the security update through our security bulletin process, although it will not be ready for this month’s bulletin release.

Finally, given our ability to detect exploit attempts for this issue, we are able to closely monitor the threat landscape and will notify customers if we see any indication of increased risk. As previously stated, the risk for customers remains low. However, that is subject to change so we encourage customers to either apply the workaround or ensure their anti-malware vendor has added new signatures based on the information we’ve provided them to ensure protections are in place for this issue.

According to Symantec, the Duqu zero-day vulnerability was exploited via a rigged Word .doc and gave the hackers remote code execution once the file was opened.

Duqu, which is believed to be linked to Stuxnet,  is highly specialized Trojan capable of gathering intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party.

* Image source: Maggiejumps’ Flickr photostream (Creative Commons 2.0)

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
54
Comments

Join the conversation!

Just In

dsfsdfd
jywhy888 7th Mar
Wholesale Toys Wholesale Banner http://www.chinawholesaletown.com/wholesale-Flash-Gift/ World Cup Products
Manicure Set Garden Decorations http://www.chinawholesaletown.com/wholesale-Tellurion/ Umbrella
Lunch Box Wholesale Mouse http://www.chinawholesaletown.com/wholesale-Clothes-Rack/ Wedding Favors
Wine Set Industrial Supplies http://www.chinawholesaletown.com/wholesale-Pen-Holder/ Scarf
Wholesale Sticker Wholesale Stationery http://www.chinawholesaletown.com/wholesale-Waterproof-Case/ Poncho
Wholesale Clothing Wholesale Flag http://www.chinawholesaletown.com/wholesale-Wine-Set/ Ruler
Wholesale Flashlight Wholesale Helmet http://www.chinawholesaletown.com/wholesale-MP3---MP4---MP5-Player/ lable
Wholesale Wallet Writing Instrument http://www.chinawholesaletown.com/ Baby Products Suppliers
Wholesale Lanyard Wholesale Pin http://www.chinawholesaletown.com/ Book Light
Lady Beauty Care Wholesale Earphone http://www.chinawholesaletown.com/wholesale-Silicone/ Earphone
Electroluminescent Wholesale Gift Bags http://www.chinawholesaletown.com/wholesale-Solar-Products/ Fishing Supplies
Wholesale Badge Advertising Material http://www.chinawholesaletown.com/wholesale-Stuffed-Animals/ Vase
Wholesale Speakers Pen Holder http://www.chinawholesaletown.com/wholesale-Racks/ Furniture
Wholesale Coaster Wholesale Magnifier http://www.chinawholesaletown.com/wholesale-Camera/ Mirror
Wholesale Compass Wholesale Whistle http://www.chinawholesaletown.com/ Audio Video Equipment
Poncho Raincoat Wholesale Mp3 http://www.chinawholesaletown.com/wholesale-Glasses/ Mobile Phone
Health Care Products Wholesale Hardware Tools http://www.chinawholesaletown.com/wholesale-Recorder-Pen/ Pin
Wholesale Flag Wholesale Binoculars http://www.chinawholesaletown.com/wholesale-Business-Gift/ China Wholesale
Audio Video Equipment Coca Cola Gifts http://www.chinawholesaletown.com/wholesale-Sport-Items/ Coin Bank
Wholesale Mouse Wholesale Puzzle http://www.chinawholesaletown.com/wholesale-Fan/ Scissors
Wholesale Calendar Wholesale Racks http://www.chinawholesaletown.com/wholesale-Apron/ Jewelry
Wholesale Umbrella Electroluminescent http://www.chinawholesaletown.com/wholesale-Entertainment/ First Aid Kit
Wholesale Whistle Wholesale Scale http://www.chinawholesaletown.com/wholesale-Pen/ Clothes Rack
Wholesale Towel Entertainment Supplies http://www.chinawholesaletown.com/wholesale-Dartboard/ Dartboard
Wholesale Glasses Fishing Supplies http://www.chinawholesaletown.com/wholesale-Binoculars/ USB Flash Drive
Reflective Safety Vest Wholesale Pom Poms http://www.chinawholesaletown.com/wholesale-Ashtray/ Watch
Bottle Opener Wholesale Mobile Phone http://www.chinawholesaletown.com/wholesale-Kitchenware/ Pedometer
Wholesale Banner Wholesale Clap Hands http://www.chinawholesaletown.com/wholesale-Radio/ Calculator
Wholesale Clap Hands Wholesale USB Products http://www.chinawholesaletown.com/wholesale-Cup/ Banner
Garden Decorations Wholesale Speakers http://www.chinawholesaletown.com/wholesale-Bag/ Frisbee
Wholesale Cards Sport Support Products http://www.chinawholesaletown.com/wholesale-Helmet/ Speakers
Wholesale Halloween Gift Men Beauty Care http://www.chinawholesaletown.com/wholesale-Book-Light/ Pen Holder
Wholesale Bracelet Silicone Products http://www.chinawholesaletown.com/wholesale-Medicine-Instrument/ Fan
Christmas Gifts Outdoor Leisure Products http://www.chinawholesaletown.com/wholesale-Money-Bank/ Recorder Pen
Wholesale Scissors Wholesale Lighter http://www.chinawholesaletown.com/wholesale-Jewelry/ Heating Products
Wholesale Candle Wholesale Golf Products http://www.chinawholesaletown.com/wholesale-Clothing/ Stuffed Animals
Wholesale Lighter Wholesale Stress Ball http://www.chinawholesaletown.com/wholesale-Water-Bottle/ Cap
0 Votes
+ -
PDF killer...
wright_is 4th Nov
The FixIt kills the ability to export to PDF in Office 2010 (I assume the same is true in 2007).

I installed the fix this morning, then I needed to export an MS Project plan as PDF and it just did nothing... After 3 or 4 attempts, I switched to Word and tried to generate a PDF from there, at least Word comes up with an error message!

I removed the FixIt and PDF worked again...

I am in two minds, whether to leave the machine unfixed and be able to generate PDFs (something I regularly have to do) or enable/disable the FixIt constantly.
0 Votes
+ -
Nice post
ego.sum.stig@... 4th Nov
Thanks for what and how you posted.
@wright_is
I suppose if neither solution seems acceptable, you could possibly work around the issue by installing software that creates a 'print to PDF' system printer. It's probably a bit less convenient to send your document to that virtual printer, but it could probably get you through to the next patch when the problem is really fixed.
@CFWhitman If you have Adobe Acrobat, you have Adobe PDF as a "system" printer ("Distiller"). Creating PDFs from Office (or other software) makes overly large, poor quality PDFs. Distiller is the only way to make true press quality PDFs.
@CFWhitman Yeah, the post was more to inform, that the fix introduces problems.

I don't tend to surf to unsecure sites or download dodgy files, so I should be reasonably safe - unless another machine on the network gets infected or a major site gets hacked.

I have been thinking about one of the free PDF print solutions as a stop-gap.
@wright_is
from untrusted sites!
0 Votes
+ -
@kd5auq
that doesn't mean that it can only be achieved from Word. They used a font vulnerability. IE uses fonts. It doesn't take a rocket scientist to understand that this vulnerability could potentially be exploited directly from any Microsoft application that uses fonts, which isn't just Word.
0 Votes
+ -
Firefox loads t2embed.dll
Rabid Howler Monkey Updated - 6th Nov
@jasonp@... I just checked Firefox v3.6.23 with Sysinternals Process Explorer. The dll in question, t2embed.dll, is loaded for Firefox as I write this post at ZDNet.com.

Edit: Looked into this a bit deeper. The NoScript add-on, by default, treats fonts just as it does other active embeddings and forbids @font-face for untrusted sites:

http://hackademix.net/2010/03/24/why-noscript-blocks-web-fonts/

Yet another reason to use NoScript with Firefox.

In addition, Mozilla added support for the OTS font sanitizer to Firefox v3.6.13 (and I believe that Chrome has this now too):

http://www.mozilla.org/security/announce/2010/mfsa2010-78.html
@wright_is
Hi happy
Thanks for letting people know. Also for letting people know they can undo things to get back to unpatched if they have the problem too.

There are various other tools for creating Pdf. It's possible to install LibreOffice alongside MS Office and still keep MS Office as the main & default office suite.

@Ryan Naraine
I definitely appreciate the original article. It is this sort of thing that keeps me tuned in to ZdNet.

Does the vulnerability only affect MS Office or does it also affect OpenOffice & LibreOffice too?
Thanks and regards from
Tom happy
@Tom6 I haven't tried it with OpenOffice or LibreOffice. We use Office 2010 here and switching between OpenOffice and MS Office is a pain, mainly due to the wasted hours reformatting, so OO.o wouldn't be an option for generating PDF, even if it worked.

I worked for a long time on OO.o, but found out very quickly, that having a Windows machine in the corner, with MS Office on it was a necessity, if I was exchanging documents with other businesses, as the OO.o interpretation of how a .doc or .ppt should look differs wildly from how MS interpret it - pagination and formatting go haywire on anything but the most simple of documents.
0 Votes
+ -
Probably not......
linux for me 7th Nov
@Tom6

Since linux does not normally use dll files, there would not be any risk.
0 Votes
+ -
@Tom6 wrote:
"Does the vulnerability only affect MS Office or does it also affect OpenOffice & LibreOffice too?

I am going to make an *educated guess* that neither OpenOffice nor LibreOffice embed TrueType (or any other) fonts based on these two links:

"Re: [libreoffice-users] I want font embedding to be enabled today.
http://listarchives.libreoffice.org/global/users/msg11729.html

"[Issue] Embedded Fonts
http://user.services.openoffice.org/en/forum/viewtopic.php?f=7&p=45326
0 Votes
+ -
What's the worst that could happen?
Joe.Smetona Updated - 5th Nov
@wright_is ... What are your chances of becoming infected? It seems like a difficult thing to fix properly, possibly the reason it's taking a greater amount of time. Leaving it unprotected with no problems seems viable especially if you don't open unsolicited Word documents.
@Joe.Smetona They haven't had any lead time to get it fixed for this month, even if the patch was relatively simple to implement, you probably have at couple of weeks worth of testing, to ensure that it doesn't break anything - like this fixit currently does.

As to chances of being infected? Web browsers, like Firefox, use the library, so it only takes one malformed website...
Microsoft has really become a thorn in the side -- it's now time to remove the dual boot, kick out windows and retain Linux.
0 Votes
+ -
My netbook
Joe.Smetona Updated - 6th Nov
@retired_gfx@... My Acer netbook has 64 bit Windows and I set up dual boot with Linux Mint. We use Linux and I will boot Windows to allow the updates to run. I installed Avira when I first got it and now, Avira is throwing up "you're infected" warning messages when just trying to let the updates run. This is in contrast to using Linux for 9 years with no AV and no infection issues. Any use of Windows is a big step down. It's so nice to have an OS that runs without attention and doesn't demand extra labor to remove malware.

I've said this many times before: People posting here, for the most part, maintain one Windows computer and deal with malware and virus updates and maintenance. When you maintain 10-100 computers, having Windows will kill you. Linux on the other hand does not require attention.
@retired_gfx@...

"This is in contrast to using Linux for 9 years with no AV and no infection issues."

Which is exactly my experience with 10+ years of Windows happy. Even a minimal amount of preventative maintenance goes a long way. It's no longer the real hassle of the Windows 9x days.

"When you maintain 10-100 computers, having Windows will kill you."

Not really, where I work everything is on servers and we just reimage clients with issues. With a bit of preventative maintenance, that's pretty rare. Our new security guy is pretty good at keeping up with patches.
0 Votes
+ -
dsfsdfd
jywhy888 7th Mar
Wholesale Toys Wholesale Banner http://www.chinawholesaletown.com/wholesale-Flash-Gift/ World Cup Products
Manicure Set Garden Decorations http://www.chinawholesaletown.com/wholesale-Tellurion/ Umbrella
Lunch Box Wholesale Mouse http://www.chinawholesaletown.com/wholesale-Clothes-Rack/ Wedding Favors
Wine Set Industrial Supplies http://www.chinawholesaletown.com/wholesale-Pen-Holder/ Scarf
Wholesale Sticker Wholesale Stationery http://www.chinawholesaletown.com/wholesale-Waterproof-Case/ Poncho
Wholesale Clothing Wholesale Flag http://www.chinawholesaletown.com/wholesale-Wine-Set/ Ruler
Wholesale Flashlight Wholesale Helmet http://www.chinawholesaletown.com/wholesale-MP3---MP4---MP5-Player/ lable
Wholesale Wallet Writing Instrument http://www.chinawholesaletown.com/ Baby Products Suppliers
Wholesale Lanyard Wholesale Pin http://www.chinawholesaletown.com/ Book Light
Lady Beauty Care Wholesale Earphone http://www.chinawholesaletown.com/wholesale-Silicone/ Earphone
Electroluminescent Wholesale Gift Bags http://www.chinawholesaletown.com/wholesale-Solar-Products/ Fishing Supplies
Wholesale Badge Advertising Material http://www.chinawholesaletown.com/wholesale-Stuffed-Animals/ Vase
Wholesale Speakers Pen Holder http://www.chinawholesaletown.com/wholesale-Racks/ Furniture
Wholesale Coaster Wholesale Magnifier http://www.chinawholesaletown.com/wholesale-Camera/ Mirror
Wholesale Compass Wholesale Whistle http://www.chinawholesaletown.com/ Audio Video Equipment
Poncho Raincoat Wholesale Mp3 http://www.chinawholesaletown.com/wholesale-Glasses/ Mobile Phone
Health Care Products Wholesale Hardware Tools http://www.chinawholesaletown.com/wholesale-Recorder-Pen/ Pin
Wholesale Flag Wholesale Binoculars http://www.chinawholesaletown.com/wholesale-Business-Gift/ China Wholesale
Audio Video Equipment Coca Cola Gifts http://www.chinawholesaletown.com/wholesale-Sport-Items/ Coin Bank
Wholesale Mouse Wholesale Puzzle http://www.chinawholesaletown.com/wholesale-Fan/ Scissors
Wholesale Calendar Wholesale Racks http://www.chinawholesaletown.com/wholesale-Apron/ Jewelry
Wholesale Umbrella Electroluminescent http://www.chinawholesaletown.com/wholesale-Entertainment/ First Aid Kit
Wholesale Whistle Wholesale Scale http://www.chinawholesaletown.com/wholesale-Pen/ Clothes Rack
Wholesale Towel Entertainment Supplies http://www.chinawholesaletown.com/wholesale-Dartboard/ Dartboard
Wholesale Glasses Fishing Supplies http://www.chinawholesaletown.com/wholesale-Binoculars/ USB Flash Drive
Reflective Safety Vest Wholesale Pom Poms http://www.chinawholesaletown.com/wholesale-Ashtray/ Watch
Bottle Opener Wholesale Mobile Phone http://www.chinawholesaletown.com/wholesale-Kitchenware/ Pedometer
Wholesale Banner Wholesale Clap Hands http://www.chinawholesaletown.com/wholesale-Radio/ Calculator
Wholesale Clap Hands Wholesale USB Products http://www.chinawholesaletown.com/wholesale-Cup/ Banner
Garden Decorations Wholesale Speakers http://www.chinawholesaletown.com/wholesale-Bag/ Frisbee
Wholesale Cards Sport Support Products http://www.chinawholesaletown.com/wholesale-Helmet/ Speakers
Wholesale Halloween Gift Men Beauty Care http://www.chinawholesaletown.com/wholesale-Book-Light/ Pen Holder
Wholesale Bracelet Silicone Products http://www.chinawholesaletown.com/wholesale-Medicine-Instrument/ Fan
Christmas Gifts Outdoor Leisure Products http://www.chinawholesaletown.com/wholesale-Money-Bank/ Recorder Pen
Wholesale Scissors Wholesale Lighter http://www.chinawholesaletown.com/wholesale-Jewelry/ Heating Products
Wholesale Candle Wholesale Golf Products http://www.chinawholesaletown.com/wholesale-Clothing/ Stuffed Animals
Wholesale Lighter Wholesale Stress Ball http://www.chinawholesaletown.com/wholesale-Water-Bottle/ Cap
THX Ryan:

And we have to wait at least a month for a real fix???
0 Votes
+ -
@Merlin the Wiz
It is a myth that MS only releases patches once a month.
doesn't sound like much of a fix at this point... with hundreds of laptops and pcs, the thought of deploying it is really ugly, even if you ignore the pdf issue, above. I think I will wait til it rolls up in SUS to deploy.
@charliegalliher: doesn't sound like much of a fix at this point... with hundreds of laptops and pcs, the thought of deploying it is really ugly, even if you ignore the pdf issue, above.

...taken as gospel. Did you even confirm the problem?
@charliegalliher
It's a .MSI file, so you should be able to deploy it via GPO from the comfort of your office, between cups of coffee happy I'm assuming anyone with hundreds of Windows PCs runs an AD domain... if yours are all free-range, you have my sincere sympathies.
This reads like a very poor piece of design / broken security model. Why does a font parser require kernel level privileges?
@timcoote No it does not. That is why it is a vulnerability. The font parser has a bug in it which allows code to be injected and executed, which in turn can elevate privileges.
@1773 Even if there's code being 'injected and executed', unless the code is subverting the security model, it should not be possible for the parser, running with the privileges of a normal user to get elevated privileges, unless there's a bug in the kernel. Has someone been taking shortcuts and not running with minimum required privileges for the parser? Or can we identify any behaviour of a font parser that requires kernel privileges?

Executing arbitrary code with the privileges of the user is bad enough, but with kernel privileges it's very serious.
For individuals, your risk is low if you only visit trusted sites and only open trusted documents. In addition, your antivirus should detect the malware that exploits this vulnerability.
Which versions of Windows does this affect?
@techadmin.cc@...
From the Security Advisory (You did the right thing by not reading it. It contains fonts. (;o):
Affected Software
Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2**
Windows Server 2008 for x64-based Systems Service Pack 2**
Windows Server 2008 for Itanium-based Systems Service Pack 2
Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1**
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

**Server Core installation not affected. This advisory does not apply to supported editions of Windows Server 2008 or Windows Server 2008 R2 as indicated, when installed using the Server Core installation option. For more information on this installation option, see the TechNet articles, Managing a Server Core Installation and Servicing a Server Core Installation. Note that the Server Core installation option does not apply to certain editions of Windows Server 2008 and Windows Server 2008 R2; see Compare Server Core Installation Options.
@Still Lynn That is only the supported versions of Windows which are affected.

Windows 2000 Professional
Windows 2000 Server
Windows XP
Windows XP SP1
Windows XP SP2
Windows Vista
Windows Vista SP1

are also affected (no idea about Win 9x), but they are no longer supported. You need to upgrade or install the relevant service packs to get to one of the supported versions in order to get a patch.
Re: PDF issues with this fix; a PDF printer as previously mentioned would solve your problems. Not sure if we are to mention names in here; but Bullzip is a great free PDF printer.
@skudera@... Thanks, I am considering a 3rd party PDF printer. My post was more to get the point across, that there are possible compatibility problems to installing the fix, which MS didn't mention.
0 Votes
+ -
And the ABMers have told us if it isn't a virus your money isn't really gone and your identity hasn't been stolen.
0 Votes
+ -
@ye
Perhaps not, but it IS a security hole in Windows which allows the exploit to work.

As for the ABMers, yes, some of them are very tiresome, but even worse, they are outnumbered about 3 or 4 to 1 by the pro-MS trolls and shills. All the ludicrous finger-pointing and put-downs make these columns very tedious and all but unreadable.
0 Votes
+ -
Again: Who cares?
ye 5th Nov
@rahbm: Perhaps not, but it IS a security hole in Windows which allows the exploit to work.

The criteria has been set by the ABMers: If it's not a virus it's a non-event and not even newsworthy. Any post about malware that is not a virus is merely scare tactics and fear mongering.

If you disagree you'll need to take it up with the ABMers.
As for the ABMers, yes, some of them are very tiresome, but even worse, they are outnumbered about 3 or 4 to 1 by the pro-MS trolls and shills.

I think you were just talking about @ye there.

lol...
0 Votes
+ -
Bitter much?
ego.sum.stig@... 5th Nov
Perhaps you need therapy.
@ego.sum.stig@...: I'm merely stating this is a non-event given the malware in question is not a virus. If that means I'm bitter and / or need counseling what does that say about the ABMers?
0 Votes
+ -
Of course it means for them
ego.sum.stig@... 6th Nov
They are right, and you are bitter and twisted and in need of therapy.
0 Votes
+ -
@ego.sum.stig: They are right, and you are bitter and twisted and in need of therapy.

No need to specifically call attention to them.
0 Votes
+ -
Straw Man
CFWhitman 9th Nov
@ye
When the people who don't like Windows say something along those lines, what they mean is that anything that relies on the user to install it (via a phishing scam or trojan) is not really a security flaw in the operating system. That is, a passive infection vs. social engineering. Since this is a passive infection, it doesn't fall under what they mean. Therefore your statement is a straw man, and you are appearing to be purposely obtuse.

A better point to make is that at this point most Windows malware is based on social engineering rather than vulnerabilities, and this is just an exception to that. You can knock down straw men all day. It doesn't impress anyone.
There's a much better fix it: Switch to Linux or OS X
0 Votes
+ -
A drive-by now too? (Subject was previously 'Just curious')
Rabid Howler Monkey Updated - 10th Nov
What if the sender created a "specially-crafted" email with Microsoft Word as the editor and the receiver of the email viewed it with Microsoft Word. As described here:

"Outlook 2010 and Outlook 2007 use only Word as the email editor
http://support.microsoft.com/kb/933793

An advantage of using Microsoft Word as both the email editor and viewer is that 'formatting is preserved':

http://office.microsoft.com/en-us/outlook-help/about-using-word-as-your-e-mail-editor-HP005242850.aspx

Is this something that the miscreants could leverage such that just viewing an email message is all that it takes? In this case, there would be no reason for an attachment to be opened.

Edit: Probably not via an email message, as Microsoft states quite conclusively in the advisory:
"The vulnerability cannot be exploited automatically through e-mail."

Edit 2: Just found this link on @font-face in email and it only worked with Apple software:

http://www.campaignmonitor.com/blog/post/3044/does-font-face-work-in-email/

**************
** Addendum **
**************
In the Microsoft advisory under "Frequently Asked Questions" Microsoft states:
"How could an attacker exploit the vulnerability?
"There are multiple means that could allow an attacker to exploit this vulnerability, including providing documents or convincing users to visit a Web page that embeds TrueType. The specially crafted TrueType font could then exploit the vulnerability.

Visiting a web page that embeds specially-crafted TrueType font? This is a new twist. Clicking a link in an email message (yes, some people still do this). Or getting redirected from a legitimate web site that's been hacked. So, apparently one can also get pwn3d via a drive-by.
thanks Microsoft but it has not been of help, may be lets wait till the real fix comes in a month.
Thanks microsoft but it hasnot been of help unfortunately.
lets wait for the real fix as exploiters take this opportunity.
0 Votes
+ -
Apparently, applying the Microsoft fix-it induces other security updates from Microsoft!! On an XP MCE SP3 machine (that's always been kept updated), after applying the fix-it referred to in this article, Windows Automatic Updates prompted to apply the following 2 old high-priority security patches:
1) http://technet.microsoft.com/en-us/security/bulletin/MS10-001
2) http://technet.microsoft.com/en-us/security/bulletin/MS10-076

Undo the fix-it and there are no more prompts for these 2 patches. So what is the proper course of action here?
@rivsidsam@...
I noticed this on a WinXP system at work too. I think the patch-detection logic is unable to access the .DLL in question, and therefore wants you to update to get the version it's expecting to find. So you can disregard those prompts for now, just hold off for the security update.
0 Votes
+ -
hi
mcxxxx 5th Nov
thank you

toplist
0 Votes
+ -
Ah! An Adobe moment.
Brian J. Bartlett 5th Nov
@flboffin Nice FUD there. I've been using alternatives for well over a decade now, on Windows machines, and they work quite nicely with measurably fewer required security updates. For instance, Nitro PDF (the Free version, not Pro) generated pages are blown up here regularly and shows no sign of visual defects or artifacts at all, even when blown up to x16. Of course your mileage may vary when it comes to non-SVG enclosed graphics but Adobe Reader and Acrobat have similar problems as do all the other variant solutions.

Speaking frankly, I'm not into DTP or any of the related fields, and even then only as it relates to my engineering projects (CAD/CAM/CAE, systems, process, hardware & software), but trying to hold Adobe products as the one and only solution has been dead for at least a decade now. And no, I haven't worked for anyone else excepting myself for that self-same decade. You need to get out more wink.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix