Exploit code appears for Microsoft Agent bug
Proof-of-concept pops up hours after Redmond reveals critical Win2000 flaw
Computerworld - It took less than 24 hours for attackers to crank out proof-of-concept code targeting the one critical vulnerability disclosed -- and patched -- Tuesday morning by Microsoft, security researchers warned.
To call attention to the added danger, Symantec also raised the vulnerability's threat score from Tuesday's initial 7.1 (out of a possible 10) to 8.5 today.
The Windows 2000 bug -- the only one rated critical of the four patched Tuesday -- is in Windows Agent, the component that drives the operating system's interactive animated help characters. The best known, and in its time, most detested, character was dubbed "Clippy," a.k.a. the Office Assistant, a bouncy paperclip designed to answer users' questions about Microsoft Office. The Redmond, Wash. developer disabled Clippy by default as of Office XP, and put it to rest when Office 2007 debuted earlier this year.
Symantec advised users who were unable to immediately apply the patch to disable their browser's script-handling capabilities. "A successful exploit requires the execution of active content," its advisory said. "To mitigate against this and other latent vulnerabilities, disable support for active content in the browser."
VeriSign Inc. iDefense, which was credited by Microsoft for reporting the bug, also posted an advisory today; in it, the security vendor spells out how to set the "kill bit" in the Windows registry to disable the Agent ActiveX control.
Microsoft has posted its technical write-up of the Agent vulnerability in the MS07-051 security bulletin.
Tuesday's update is also a replacement for an earlier April fix of Agent, an indication that the company's developers didn't find all the bugs in the component five months ago.
Read more about Security in Computerworld's Security Topic Center.
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts