Events

Patch Tuesday October 2011

Microsoft customers have an urgent and heavy dose of patching to do today. Internet Explorer may have only one update assigned to it, but the MS11-081 cumulative update fixes eight different vulnerabilities. And these vulnerabilities impact all lines of Windows, including Windows 7 x64 all the way up through Windows Server 2008 x64 Service Pack 2.

The nice thing about it, is that on the consumer side, Microsoft has developed their update utility to handle most of the decision making for you. On the corporate side, sys admins all handle the updates their own way, which may require important compatibility and quality testing efforts.

In addition to the eight critical vulnerabilities being fixed in Internet Explorer, both consumer and corporate customers urgently need to patch Silverlight with MS11-078, which may or may not be installed on your system. Silverlight is Microsoft’s interactive media web browser plug-in (along with the Novell/Mono efforts), enabling developers to code up Silverlight applications in any .NET language (C#, etc). In other words, it’s competition for Adobe’s Flash, only without the same adoption rate at this point. Anyway, both IE and Silverlight are two software clients that are heavily used, and reliable exploitation will lead to remote code execution across the wide variety of Windows versions. It would be surprising to not see related exploits added to packs and widely used in attack attempts over the coming months. On the server side, if a IIS server processes ASP.NET pages and a malicious attacker uploads a ASP.NET page and then executes the page, the attackers’ code could be executed on the server. Please patch immediately.

Of the eight security bulletins, two are rated critical and six important, addressing 23 vulnerabilities across Internet Explorer, .NET Framework & Silverlight, Microsoft Windows, Microsoft Forefront UAG, and Microsoft Host Integration Server. MS11-077 patches a couple of interesting bugs in the core Windows drivers that expose exploitable vulnerabilities across all the supported Windows versions from Windows XP SP3 to Windows Server 2008 x64 SP2, including a use-after-free in win32k.sys leading to EoP and a font library file BoF leading to RCE.

Patch Tuesday October 2011

Your email address will not be published.

 

Reports

APT trends report Q1 2022

This is our latest summary of advanced persistent threat (APT) activity, focusing on events that we observed during Q1 2022.

Lazarus Trojanized DeFi app for delivering malware

We recently discovered a Trojanized DeFi application that was compiled in November 2021. This application contains a legitimate program called DeFi Wallet that saves and manages a cryptocurrency wallet, but also implants a full-featured backdoor.

MoonBounce: the dark side of UEFI firmware

At the end of 2021, we inspected UEFI firmware that was tampered with to embed a malicious code we dub MoonBounce. In this report we describe how the MoonBounce implant works and how it is connected to APT41.

Subscribe to our weekly e-mails

The hottest research right in your inbox