Microsoft issues workaround for Duqu attack while it prepares a patch
The temporary fix may affect some applications using embedded fonts, Microsoft said
IDG News Service - Microsoft has published code to temporarily blunt attacks against a software vulnerability exploited by Duqu, an advanced piece of malicious software still being closely analyzed by security researchers.
Microsoft is working on a patch for the vulnerability in the Win32k TrueType font parsing engine, a component of various Windows operating systems. An attacker could exploit it to load malicious code on a computer in kernel mode.
The exploit can be delivered by a malicious Microsoft Word document, researchers found. The document could be sent to a target via an e-mail attachment; opening the document would launch the attack.
Researchers from the Laboratory of Cryptography and System Security (CrySyS) in Hungary located an installer file for Duqu and discovered it used the previously unknown Windows vulnerability.
Microsoft's workarounds are a few lines of code that run at an administrative command prompt. Microsoft warned that installing the workarounds may mean that some applications that rely on embedded font technology may not display properly. The workarounds apply to Microsoft's XP, Vista and 7 operating systems as well as to various Windows Server products. The company has also published a quick fix that can be downloaded and applied.
Microsoft is due to release its monthly patches on Tuesday, but it doesn't appear the company will fix the Duqu vulnerability in time. Microsoft also occasionally releases "out-of-cycle" patches for major vulnerabilities, but it typically does not forecast if it will do so.
Microsoft could take weeks to engineer a patch, said Costin G. Raiu, director of the global research and analysis team for Kaspersky Lab.
"Fixing the vulnerability will require modifying the kernel code, which is something very delicate and risky," Rau said. "Testing the modification and patches will take a lot of time."
Creating an out-of-cyle patch could take at least two weeks, Raiu said. It is more likely the patch will be ready next month, unless the bug is reverse-engineered and more malware starts using it, he said.
Duqu has been likened to Stuxnet, although reports have differed over whether the two pieces of malware are related.
Stuxnet demonstrated a certain level of sophistication on the part of its creators, as it installed itself in Windows by exploiting four zero-day vulnerabilities -- ones that are exploited before the vendor is aware of it and able to develop a patch.
Duqu is also viewed as advanced, since exploitation of a kernel-level problem would enable it to better evade antivirus software. Duqu is believed to have been created for targeted attacks against organizations.
"We are aware of targeted attacks that try to use the reported vulnerability; overall, we see low customer impact at this time," Microsoft said in an advisory posted late Thursday.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Security for Virtualization Learn more.
- When Malware Goes Mobile: Causes, Outcomes and Cures Cybercriminals are increasingly setting their sights on smartphones and other mobile devices. Learn about platform-specific policies and strategies you can employ to protect...
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Malware and Vulnerabilities White Papers | Webcasts