<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Zero-Day Microsoft Access Exploit in Security</title>
<link>http://www.dslreports.com/forum/r19457987</link>
<description></description>
<language>en</language>
<pubDate>Sat, 26 Jul 2008 11:48:49 EDT</pubDate>
<lastBuildDate>Sat, 26 Jul 2008 11:48:49 EDT</lastBuildDate>

<item>
<title>Zero-Day Microsoft Access Exploit</title>
<link>http://www.dslreports.com/forum/remark,19457987</link>
<description><![CDATA[<A HREF="/useremail/u/789469"><b>exocet_cm</b></A> : <b>Note: attached file is e-mail in .htm format with links and images</b><br>This just in my inbox from Watchguard Firebox<br>   <blockquote><small>quote:</small><hr>Public and Unpatched: Zero Day Microsoft Access Exploit <br>Severity: Medium <br>16 November, 2007<br><br>Summary:<br>Today, a Chinese researcher released an advisory warning of a serious, zero day vulnerability affecting Windows Access 2003 (and most likely, earlier versions). By enticing one of your users into opening a malicious MDB file, an attacker can exploit this flaw to execute code on that user's computer, potentially gaining complete control of the victim's machine. If you use Microsoft Office 2003 with Access, you should implement the workarounds described in the Solution Path section of this alert until Microsoft releases a patch. <br><br>Exposure:<br>A Chinese security researcher calling himself Cocoruder released a security advisory today, describing a new, unpatched buffer overflow vulnerability in the Microsoft Jet Engine component (msjet40.dll) that Access uses to parse MDB files. By enticing one of your users into opening a maliciously crafted MDB file, an attacker can exploit this flaw to execute code on that user's computer, with that user's privileges. If the victim has local administrative privileges, the attacker could leverage this flaw to gain total control of the victim's computer. <br><br>Cocoruder released this advisory before Microsoft released a patch fixing this issue. According to Cocoruder's advisory, he contacted Microsoft about the flaw, but he claims Microsoft said they would not fix it. He further claims that in reply to Cocoruder's vulnerability disclosure, Microsoft wrote to him, "You appear to be reporting an issue with a file type Microsoft considers to be unsafe. Many programs, such as Internet Explorer and Outlook, automatically block these files. For more information, please visit &raquo;<A HREF="http://support.microsoft.com/kb/925330."" >support.microsoft.com/kb/925330."</A> <br><br>Making matters worse, Cocoruder has released a Proof-of-Concept (PoC) file that exploits this vulnerability, and proves that the flaw works. If you open his PoC file in a vulnerable version of Access, it automatically spawns Windows calculator. The LiveSecurity team has tested this PoC on a lab machine and it worked as advertised. While this particular PoC is benign, blackhat attackers could easily modify the PoC to run just about anything on your machine, instead of merely a calculator. If you use Access, you should consider this zero day flaw a serious risk.<br><br>Solution Path:<br>Microsoft hasn't patched this zero day vulnerability, and Cocoruder alleges that they do not plan to. For now you have two courses of action. First, remain aware of this vulnerability and the potential hazard that unsolicited .MDB files carry. Second, block .MDB files at your gateway. Your Firebox can help you do this (see below). <br><br>For All WatchGuard Firebox Users:<br>You can configure most WatchGuard Firebox models to block Access Database (.MDB) files at your gateway. Since most organizations typically don't need to receive Access database files from the outside world, blocking them will not affect most users. If you think your organization might be an exception to that generalization, your best choices are either to call appropriate managers whose teams use Access and inquire whether they must receive MDB files over the Internet; or, it might be more efficient (and safe) to block the filetype using your firewall and see whether anyone complains. <br><br>If you want to block .MDB files that arrive via email and the web, follow the instructions for you Watchguard Firebox product.<br><br>Status:<br>Microsoft has not released a patch for this issue. We will update you if and when they do. <br>References:<br>Cocoruder's Microsoft Jet Engine Security Advisory &raquo;<A HREF="http://ruder.cdut.net/blogview.asp?logID=227" >ruder.cdut.net/blogview.asp?logID=227</A><br>This alert was researched and written by Corey Nachreiner, CISSP.<br><hr></blockquote><br><br>Attached file is e-mail in .htm format.<br>Mods and Admins: feel free to edit/move/delete at will.<br>~exo<br><br><b>Update:</b> If you use ReportExec in your corporation understand that it relies heavily on MS Access and the Microsoft Jet Engine. This program is used widely in the Public Safety sector. Be careful opening files that use MS Access or sent to you for use in ReportExec.<br><small>--<br>"I have measured out my life with coffee spoons..." - T.S Eliot<br> Check Out the Tech Bench &raquo;<A HREF="http://johnball.wordpress.com/tech-bench/" >johnball.wordpress.com/tech-bench/</A><b><br> <b>Ma blog: &raquo;<A HREF="http://www.johndball.com" >www.johndball.com</A></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/r0/download/1241242~a12f7299160aceb6f2f61253824ff7e5/LiveSecurity%20%20Urgent%20MS%20Access%20Exploit%20Public%20and%20Unpatched.htm.zip"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>LiveSecurity&middot;&middot;&middot;.htm.zip</big></A> <small>5,435 bytes</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19457987</guid>
<pubDate>Fri, 16 Nov 2007 17:59:01 EDT</pubDate>
</item>

</channel>
</rss>
