Microsoft patches new GDI kernel flaw

But no joy for Excel users.

Microsoft has patched seven vulnerabilities in Windows, including one marked "critical" that could be triggered by attackers simply by getting users to view a malicious image or visit a malicious site.

Of the three security updates the most serious, and the one to patch first, is MS09-006, researchers said today. That update, which contains three separate vulnerabilities, contains the month's single critical bug.

"It's in all versions of Windows, it's deep in the kernel and in GDI," said Wolfgang Kandek, chief technology officer at security company Qualys. "And you could get exploited in many ways. I could send you an email or I could get you to go to a malicious website."

"MS09-006, that's just pretty evil," said Eric Schultze, chief technology officer at Shavlik Technologies LLC. "View something evil and you're hacked."

According to Microsoft, the critical vulnerability is due to "improper validation of input passed from user mode through the kernel component of GDI." The Graphics Device Interface (GDI) is the core graphics rendering component of Windows. Because the flaw is in the kernel, a successful exploit would leave the attacker with complete control of the machine.

"With the history of GDI, people will really be looking at this," predicted Andrew Storms, director of security operations at nCircle Network Security Microsoft fixed GDI three times last year, most recently in December 2008, and the Windows kernel twice. "It's like rewind, repeat," Storms said.

Attackers would use malformed WMF (Windows Metafile) or EMF (Enhanced Metafile) images to exploit the bug, Microsoft said, feeding them to users via email or hosting them on websites. Opening or viewing the images would trigger the vulnerability.

"I liked how Microsoft acknowledged that attackers could exploit this by getting users to view an email or visit a website or open a document with an evil image," said Schultze.

But because Microsoft rated the vulnerability as "3" in its Exploitability Index, indicating that it doesn't believe functional attack code is likely in the next 30 days, Storms said he was confused. "Now I'm unsure. It's obviously the riskiest vulnerability, but with the exploitability index at 3, should I really worry about it or not?"

Storms answered his own question. "I have to take the safe side, and consider it a major bug and put it at the top of the list," he said.

The other update that Kandek, Schultze and Storms agreed needed immediate attention was MS09-008, which contained four separate flaws in Windows' DNS and WNS servers. All four were pegged as "important," the second-highest ranking in Microsoft's four-step scoring system. All currently supported server editions of Windows should be patched, including Windows 2000 Server, Server 2003 and Server 2008.

"These vulnerabilities could allow a remote attacker to redirect network traffic intended for systems on the Internet to the attacker's own systems," said Microsoft. Such attacks are often referred to as "cache poisoning" attacks because they replace the legitimate addresses in a DNS server's cache with bogus destinations. DNS cache poisoning vulnerabilities gained attention last July when researcher Dan Kaminsky discovered a major flaw in the underlying DNS protocol, and organised an industry-wide patching effort to plug the hole.

"These seem to be separate from [Kaminsky's vulnerability]," said Kandek, and Schultze concurred. Storms, however, wasn't as sure.

"It sounds a lot like what we saw last summer," he countered.

But while Microsoft tagged the update as important, Schultze argued that it should be considered critical. "Microsoft seems to think that there not much likelihood of someone pulling off an exploit of this," he said, "but there was already code released for 08-037, another DNS vulnerability last year, and Microsoft rated that important, too. To me, that makes me rate this one kind of critical."

Missing from this month's updates, however, was a fix for a vulnerability in Excel that Microsoft revealed two weeks ago, and has admitted is already being used by attackers. According to researchers at Symantec, the vulnerability is a file format bug in all supported versions, including the latest - Excel 2007 on Windows and Excel 2008 for the Mac.

"We should have expected a patch," said Schultze. "And that we didn't get on, that sucks."

"No, I'm not surprised at all that it wasn't ready," said Storms. "But I wouldn't be surprised if we saw a patch in the next couple of weeks if things heat up."


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

Hacker attacks on US military jump sharply in 2009

China source of most attacks, says report

Microsoft denies building security 'backdoor' in Windows 7

Privacy organisations shouldn't read too much into NSA involvement it says

Pentagon expands exclusive deal with McAfee

Department of Defense uses McAfee products

Police arrest pair over global banking web scam

Man and woman arrested in Manchester for using notorious Zeus Trojan



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *