Unpatched Windows Vulnerability Actively Exploited in the Wild

JMH

Banned
Local time
7:27 AM
Messages
6,448
A critical Windows remote code execution vulnerability disclosed last week is already being exploited in the wild. Security companies warn that attackers are luring unsuspecting users onto malicious Web pages that leverage the flaw to install malware on their computers.

Last Thursday, Tavis Ormandy, an information security engineer at Google revealed details about a previously unknown vulnerability in the Windows Help and Support Center. Considering that his disclosure included fully working exploitation code and that Microsoft was only given five days in advance to patch the bug, many people in the information security community accused Ormandy of acting irresponsibly.

"Today, we got the first pro-active detection (Sus/HcpExpl-A) on malware that is spreading via a compromised website. This malware downloads and executes an additional malicious component (Troj/Drop-FS) on the victim’s computer, by exploiting this vulnerability," Donato Ferrante, a security researcher at Sophos, announced yesterday. "In my opinion publishing exploit code was utterly irresponsible behaviour, and I was worried that having such information floating around the internet would make it easy for cybercriminals to take advantage," Graham Cluley, the company's senior technology consultant, commented.
More -
Unpatched Windows Vulnerability Actively Exploited in the Wild - Attacks target Windows XP users - Softpedia
 

My Computer My Computer

At a glance

Win 7 Ultimate 64-bit. SP1.Intel i7 -720QM.[1.6GHz Turbo Boost 2.8GHz. 6...8 DDR 3 RAM. 1066MHZATI 1024 MB. DDR3. Radeon HD5650
Computer Manufacturer/Model Number
LAPTOP. HP Pavilion dv7-4010TX .
OS
Win 7 Ultimate 64-bit. SP1.
CPU
Intel i7 -720QM.[1.6GHz Turbo Boost 2.8GHz. 6MB Cache.]
Memory
8 DDR 3 RAM. 1066MHZ
Graphics Card(s)
ATI 1024 MB. DDR3. Radeon HD5650
Monitor(s) Displays
17.3" High Definition Brightview LCD. LED Backlit.
Screen Resolution
1600 x 900.
Hard Drives
640GB
Case
Laptop / notebook.
Mouse
Logitech Anywhere mouse. MX.
Internet Speed
ADSL [ but too slow ]
This one sounds like a,...what I call a "Reformatter" :sarc: because once this gets into your system no A/V is going to pull you out of it. Thanks for the info JMH.
 

My Computer My Computer

At a glance

Windows 7 Ult, Windows 8.1 Pro,Q9650-4.275GHz, E8600 4.5GHz, E6750-3.8GHzG.Skill PC2 9600 1200Mhz 5 5 5 15 2TGTX480
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home built
OS
Windows 7 Ult, Windows 8.1 Pro,
CPU
Q9650-4.275GHz, E8600 4.5GHz, E6750-3.8GHz
Motherboard
Evga 780i FTW
Memory
G.Skill PC2 9600 1200Mhz 5 5 5 15 2T
Graphics Card(s)
GTX480
Sound Card
Asus Xonar D2
Monitor(s) Displays
HannsG
Screen Resolution
1680X1050
Hard Drives
GSkill Phoenix Pro 120GB SSD
PSU
ThermalTake Toughpower 1000Watt modular
Case
ThermalTake XaserV
Cooling
Xigmatek S1283
Keyboard
Logitech G15
Mouse
Logitech G9
Internet Speed
T1
Sounds like another exploit that 7 users probably shouldn't worry about, just XP users. ;)
 

My Computer My Computer

At a glance

Windows 7 Professional x64 SP1Intel Core i5-2500K8 GB Corsair Vengeance Blue DDR3-1600Sapphire Radeon HD 6870 1 GB GDDR5
OS
Windows 7 Professional x64 SP1
CPU
Intel Core i5-2500K
Motherboard
Gigabyte P67X-UD3-B3
Memory
8 GB Corsair Vengeance Blue DDR3-1600
Graphics Card(s)
Sapphire Radeon HD 6870 1 GB GDDR5
Monitor(s) Displays
Samsung SyncMaster T220HD
Screen Resolution
1680x1050
Hard Drives
120 GB Corsair Force SSD + 320 GB Seagate Barracuda SATA2 + 2 TB My Book Elite
PSU
Corsair 650W
Internet Speed
50 Mbps
Wonder how much more of this it will take to get people off XP...?
 

My Computer My Computer

At a glance

Windows 7 Home Premium x64Intel Core i7-2600 @3.40GHz8.00GB DDR3NVIDIA GeForce GTX 555 w/1.0GB RAM
Computer Manufacturer/Model Number
Alienware X51
OS
Windows 7 Home Premium x64
CPU
Intel Core i7-2600 @3.40GHz
Memory
8.00GB DDR3
Graphics Card(s)
NVIDIA GeForce GTX 555 w/1.0GB RAM
Monitor(s) Displays
BenQ XL2420TX
Screen Resolution
1920x1080@120Hz
Hard Drives
1TB
PSU
330-watt
Keyboard
Logitech Wireless Illuminated Keyboard K800
Mouse
Razer Orochi
Internet Speed
Campus Internet
Wonder how much more of this it will take to get people off XP...?
It's not likely stuff like this which really encourages people to switch. most who are using XP are on old machines and likely will be on XP simply until they purchase a new computer.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Q9550 2.83Ghz OC'd to 3.40Ghz8GB G.Skill PI DDR2-800, 4-4-4-12 timingsEVGA 1280MB Nvidia GeForce GTX570
Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
Wonder how much more of this it will take to get people off XP...?
It's not likely stuff like this which really encourages people to switch. most who are using XP are on old machines and likely will be on XP simply until they purchase a new computer.

What about the people that swear up and down that nothing will ever get them off XP? I look forward to seeing their compatibility rot around them when all the developers realize that MS is never going to just re-release XP (which is apparently what the aforementioned people want)... At least the holdouts are fewer this time around, due to the vast superiority of Win 7...
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Home Premium x64Intel Core i7-2600 @3.40GHz8.00GB DDR3NVIDIA GeForce GTX 555 w/1.0GB RAM
Computer Manufacturer/Model Number
Alienware X51
OS
Windows 7 Home Premium x64
CPU
Intel Core i7-2600 @3.40GHz
Memory
8.00GB DDR3
Graphics Card(s)
NVIDIA GeForce GTX 555 w/1.0GB RAM
Monitor(s) Displays
BenQ XL2420TX
Screen Resolution
1920x1080@120Hz
Hard Drives
1TB
PSU
330-watt
Keyboard
Logitech Wireless Illuminated Keyboard K800
Mouse
Razer Orochi
Internet Speed
Campus Internet
This is why it is good to be a techie nerd, Windows HELP? :p

I disable that service immediately after every wipe and drop with all the other silly nonsense wasting resources that M$ made default.

Try Boostspeed, I swear by and at it for tweaking ease. ;)

...and all firewall programs are not equal, which I found out last year, and switched, I was pretty perturbed that my trusty old one turned out to be unacceptable.
 

My Computer My Computer

At a glance

Windows 7 Ultimate Retail Box (64-bit install...AMD FX-8350 CPU v1.15 (or 1.0F) BIOS was requ...8G CAS-7 G-Skill DDR3 @1333 (2 fours) [mobo n...Radeon HD 7950 [3 gigs of GDDR5] MSI Twin Fro...
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built Custom
OS
Windows 7 Ultimate Retail Box (64-bit installed) + Service Pack 1
CPU
AMD FX-8350 CPU v1.15 (or 1.0F) BIOS was required!
Motherboard
MSI 890FXA-GD70
Memory
8G CAS-7 G-Skill DDR3 @1333 (2 fours) [mobo nonOC max rec'd]
Graphics Card(s)
Radeon HD 7950 [3 gigs of GDDR5] MSI Twin Frozr model
Sound Card
Realtek High Definition Audio (onboard mobo, ALC-889 chip)
Monitor(s) Displays
2 WS LED Monitors: One LG One Viewsonic
Screen Resolution
1920 by 1080
Hard Drives
SSD for OS: Samsung 840 Pro
SSD for VM and utilities: Adata SX900
7200 RPM SATA HDs for the rest: Hitachi and Seagate
PSU
Corsair TX850 - 850W max, in service since August 2010.
Case
Thermaltake Armor A90
Cooling
Thermaltake Spin Q CPU Cooler, in service since August 2010
Keyboard
Logitech G11
Mouse
Logitech M310 Wireless
Internet Speed
100 Megabit broadband supposedly upgraded from 50 (Cable)
Antivirus
Bitdefender Internet Security 2014 suite
Browser
Pale Moon 64-bit main, also IceDragon, Opera, and Maxthon.
Other Info
CompTIA A+ certified (220-800 series) in July 2013.
Back
Top