Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

Exploit code appears for Microsoft Agent bug

Less than 24 hours after Microsoft released September's security patches, a proof-of-concept JavaScript exploit code that attacks Microsoft Agent was posted online


It took less than 24 hours for attackers to crank out proof-of-concept code targeting the one critical vulnerability disclosed -- and patched -- Tuesday morning by Microsoft, security researchers warned.

Early Wednesday, analysts with Symantec's DeepSight threat network alerted customers of JavaScript exploit code for the critical vulnerability in Windows 2000 that was revealed in Microsoft's monthly patch cycle. The proof-of-concept was posted to the Internet by someone with a Brazilian e-mail address. An hour-and-a-half later, Symantec updated its alert to say that additional exploit code was also available to users of Immunity's popular CANVAS penetration testing ("pentest") software.

To call attention to the added danger, Symantec also raised the vulnerability's threat score from Tuesday's initial 7.1 (out of a possible 10) to 8.5 today.

The Windows 2000 bug -- the only one rated critical of the four patched Tuesday -- is in Windows Agent, the component that drives the operating system's interactive animated help characters. The best known, and in its time, most detested, character was dubbed "Clippy," a.k.a. the Office Assistant, a bouncy paperclip designed to answer users' questions about Microsoft Office. The developer disabled Clippy by default as of Office XP and put it to rest when Office 2007 debuted earlier this year.

The JavaScript-based exploit fits nicely with analysis made yesterday by Tom Cross, a researcher with IBM Internet Security Systems' X-Force. The vulnerability, said Cross Tuesday, is in the Agent ActiveX control, which are typically exploited by duping users into visiting Web sites where malicious script code has been planted, and "attackers will use a pretty common attack vector," he said Tuesday. The quick appearance today of proof-of-concept also matches his initial impression. "This uses a pretty common attack vector, and it fits the profile of a lot of bugs."

Symantec advised users who were unable to immediately apply the patch to disable their browser's script-handling capabilities. "A successful exploit requires the execution of active content," its advisory said. "To mitigate against this and other latent vulnerabilities, disable support for active content in the browser."

VeriSign iDefense, which was credited by Microsoft for reporting the bug, also posted an advisory today; in it, the security vendor spells out how to set the "kill bit" in the Windows registry to disable the Agent ActiveX control.

Microsoft has posted its technical write-up of the Agent vulnerability in the MS07-051 security bulletin.

Tuesday's update is also a replacement for an earlier April fix of Agent, an indication that the company's developers didn't find all the bugs in the component five months ago.

Computerworld is an InfoWorld affiliate


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





COMPREHENSIVE DATA PROTECTION AND DISASTER RECOVERY
Traditional backup and recovery is becoming irrelevant. You need more. Watch this InfoWorld and Dell Equallogic webcast to learn the current trends in Comprehensive Data Protection and Disaster Recovery for VMware Virtual Infrastructure. Sponsored by Dell Equallogic:

»  Click here to view this Webcast
  Protection for Remote Sites and Branch Offices
This Whitepaper reviews the challenges of creating appropriate data protection, especially for small and midsize companies with remote and branch offices. It offers suggestions on how you can choose the most appropriate data protection solution for your company's needs. Sponsored by Overland

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 12/04/2008

Sun enters RIA realm with JavaFX, Adobe says it will cut 600 jobs, AMD...

 
 
 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist
TecChannel :: TecCommunity