Vista zero-day exploit for sale?
Trend Micro spots post on hacker forum; 0day not cheap
IDG News Service - An online criminal has offered to sell software that exploits an unpatched bug in Microsoft Corp.'s Windows Vista operating system, according to security vendor Trend Micro Inc.
The code was offered for sale in an underground hacker discussion forum last month, said Raimund Genes, Trend Micro's chief technology officer. The asking price? $50,000.
Genes didn't know if the code actually worked as advertised, or whether it was even purchased, but he said that it would have been difficult for the seller to have been involved with this particular forum without providing at least one reliable sample. "I think that definitely he had something," Genes said. "The question is whether somebody paid for this."
If the offer is legitimate, it would be the first serious bug reported in Vista since it was released to business customers at the end of November. The consumer version of Vista is set to ship next month.
Microsoft is investigating Trend's claims but has "not been contacted directly by any parties about this vulnerability report, nor are we directly involved in the forums in which vulnerabilities are reportedly traded," the company said in a statement.
If someone did pay for the code -- called a "zero-day" or "0day" exploit -- it was purchased at a premium price. According to Genes, a similar exploit for Internet Explorer would command about $5,000. "This was way more," he said. "Maybe the person said, 'This is the first working exploit on Vista, so I can charge a premium.'"
Because Vista is not as widely adopted as Microsoft's XP or Windows Server 2003 operating systems, criminals would have fewer potential victims to attack with the code.
"To be honest [the price for a Vista zero day] should probably be lower," said Joe Telafici, vice president of Avert operations with McAfee Inc. "There's nobody to infect with it."
There have been far fewer vulnerability disclosures in the weeks up to Vista's commercial release than there were when XP was introduced, Telafici said. That's partially due to the expansion of the underground marketplace for software bugs, he said. While most hackers were motivated by the fame and glory just a few years ago, they growth of cybercrime has introduced a new breed of more stealthy professionals, security experts say.
Criminals who plan to use Vista vulnerabilities "are going to be holding them close to their chest until they are ready to release them," Telafici said. "I wouldn't be amazed if we saw vulnerabilities popping up over the next year that were found now."
- Troubleshooting Common Issues in VoIP Learn more about Voice over Internet Protocol (VoIP), including common VoIP metrics used, best practices in VoIP management and tips and tricks for...
- 2013 Network Management Software (NMS) Buyers Guide This white paper contains an independent comparison study of six different network management solutions and provides guidance on how you can choose the...
- Rightsizing Your Network Performance Management Solution: 4 Case Studies This white paper discusses challenges encountered as organizations search for the most cost-effective network performance management solution.
- Global Growing Pains: Tapping into B2B Integration Services to Overcome Global Expansion Challenges A recent survey by IDG Research explored both the challenges and pain points companies face when growing globally, as well as the capabilities...
- E-Signature RFP Checklist Webcast If your organization is looking to adopt e-signatures, you may be overwhelmed by the number of providers that offer seemingly similar solutions. How...
- Cloud and Collaboration: Driving Your Business Value Mission Critical Cloud from Peer 1 Hosting is enterprise-grade. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!