www.broadbandreports.com
  
Search:  

 
   AllHot TopicsCable SupportTelco SupportHardware etcSecurityClubsGallery»»






how-to block ads


 
Forums » Up and Running » Security » Security » Zero-Day Microsoft Access Exploit
 
Search Topic:
  Social:
topic feed
 
Posting
toggle:
flat / full
normal / watch
Post a:
Post a:
AVG update manager errors often »
« Hardware or Software issue?  
AuthorAll Replies


exocet_cm
Signal 26's Rock
Premium
join:2003-03-23
New Orleans, LA
clubs:
·Cox HSI
·Network Telephone ..
·Suddenlink
·Cingular Wireless
·AT&T Southeast


edit:
November 16th, @06:07PM

 Zero-Day Microsoft Access Exploit

Note: attached file is e-mail in .htm format with links and images
This just in my inbox from Watchguard Firebox
quote:
Public and Unpatched: Zero Day Microsoft Access Exploit
Severity: Medium
16 November, 2007

Summary:
Today, a Chinese researcher released an advisory warning of a serious, zero day vulnerability affecting Windows Access 2003 (and most likely, earlier versions). By enticing one of your users into opening a malicious MDB file, an attacker can exploit this flaw to execute code on that user's computer, potentially gaining complete control of the victim's machine. If you use Microsoft Office 2003 with Access, you should implement the workarounds described in the Solution Path section of this alert until Microsoft releases a patch.

Exposure:
A Chinese security researcher calling himself Cocoruder released a security advisory today, describing a new, unpatched buffer overflow vulnerability in the Microsoft Jet Engine component (msjet40.dll) that Access uses to parse MDB files. By enticing one of your users into opening a maliciously crafted MDB file, an attacker can exploit this flaw to execute code on that user's computer, with that user's privileges. If the victim has local administrative privileges, the attacker could leverage this flaw to gain total control of the victim's computer.

Cocoruder released this advisory before Microsoft released a patch fixing this issue. According to Cocoruder's advisory, he contacted Microsoft about the flaw, but he claims Microsoft said they would not fix it. He further claims that in reply to Cocoruder's vulnerability disclosure, Microsoft wrote to him, "You appear to be reporting an issue with a file type Microsoft considers to be unsafe. Many programs, such as Internet Explorer and Outlook, automatically block these files. For more information, please visit »support.microsoft.com/kb/925330."

Making matters worse, Cocoruder has released a Proof-of-Concept (PoC) file that exploits this vulnerability, and proves that the flaw works. If you open his PoC file in a vulnerable version of Access, it automatically spawns Windows calculator. The LiveSecurity team has tested this PoC on a lab machine and it worked as advertised. While this particular PoC is benign, blackhat attackers could easily modify the PoC to run just about anything on your machine, instead of merely a calculator. If you use Access, you should consider this zero day flaw a serious risk.

Solution Path:
Microsoft hasn't patched this zero day vulnerability, and Cocoruder alleges that they do not plan to. For now you have two courses of action. First, remain aware of this vulnerability and the potential hazard that unsolicited .MDB files carry. Second, block .MDB files at your gateway. Your Firebox can help you do this (see below).

For All WatchGuard Firebox Users:
You can configure most WatchGuard Firebox models to block Access Database (.MDB) files at your gateway. Since most organizations typically don't need to receive Access database files from the outside world, blocking them will not affect most users. If you think your organization might be an exception to that generalization, your best choices are either to call appropriate managers whose teams use Access and inquire whether they must receive MDB files over the Internet; or, it might be more efficient (and safe) to block the filetype using your firewall and see whether anyone complains.

If you want to block .MDB files that arrive via email and the web, follow the instructions for you Watchguard Firebox product.

Status:
Microsoft has not released a patch for this issue. We will update you if and when they do.
References:
Cocoruder's Microsoft Jet Engine Security Advisory »ruder.cdut.net/blogview.asp?logID=227
This alert was researched and written by Corey Nachreiner, CISSP.

Attached file is e-mail in .htm format.
Mods and Admins: feel free to edit/move/delete at will.
~exo

Update: If you use ReportExec in your corporation understand that it relies heavily on MS Access and the Microsoft Jet Engine. This program is used widely in the Public Safety sector. Be careful opening files that use MS Access or sent to you for use in ReportExec.
--
"I have measured out my life with coffee spoons..." - T.S Eliot
Check Out the Tech Bench »johnball.wordpress.com/tech-bench/
Ma blog: »www.johndball.com
Forums » Up and Running » Security » SecurityAVG update manager errors often »
« Hardware or Software issue?  

Most commented news this week
· [154] Comcast Van Race Injures 3-Year-Old
· [99] EA Scales Back 'Internet Required' DRM
· [82] Sprint Hemorrhaging Wireless Subscribers
· [74] ISPs To Start Booting More P2P Users
· [74] Mozilla Considering Opt-In Browsing Tracking
· [70] Canadian Regulators Deny Relief For Bell Canada Traffic Shaping
· [57] Baby Bell Neglect of Vanilla DSL Could Spell Trouble
· [52] An Inside Look At RIAA DMCA Letter Generation
· [51] Missouri University Makes Kids Take Copyright Quiz To Use P2P
· [48] Verizon: Stop Yer Broadband Bellyachin'
Saturday, 17-May
10:23:57
Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
8th year online! © 1999-2008 dslreports.com.
page compression OFF