Microsoft Security Advisory (2286198)

    Microsoft Security Advisory (2286198)


    Posted: 16 Jul 2010
    Microsoft has released Security Advisory 2286198, which addresses a publicly reported vulnerability in Windows Shell. From the Security Advisory:

    "The vulnerability exists because Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the user clicks the displayed icon of a specially crafted shortcut. This vulnerability is most likely to be exploited through removable drives."
    If AutoPlay is disabled, particularly for USB devices, in order for the vulnerability to be exploited, it would be necessary to manually browse to the root folder of the removable disk. AutoPlay for removable disks is automatically disabled on Windows 7. In the event you have enabled AutoPlay, it is strongly advised that it be disabled.

    To disable AutoPlay the prerequisites in Microsoft KB Article 967715 must first be installed. If your computer is up-to-date, they are already installed. The KB Article also includes instructions on "How to disable the Autorun functionality in Windows".

    Note that it is additionally reported on the MSRC Blog that, "In the wild, this vulnerability has been found operating in conjunction with the Stuxnet malware". For more information on Stuxnet, see the MMPC blog post. Of further interest, as the MSRC Blog reports

    "signatures in up-to-date versions of Microsoft Security Essentials, Microsoft Forefront Client Security, Windows Live OneCare, the Forefront Threat Management Gateway, and the Windows Live Safety Platform protect customers against the Stuxnet malware."
    References:

    Posted By: Corrine
    16 Jul 2010



  1. Posts : 22
    Win 7
       #1

    This applies to

    Microsoft Windows 2000
    Windows XP Service Pack 2
    Windows XP Service Pack 3
    Windows Server 2003 Service Pack 1
    Windows Server 2003 Service Pack 2

    Not Win 7
      My Computer


  2. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
    Thread Starter
       #2

    Hi, justalogin.

    AutoPlay for removable disks is automatically disabled on Windows 7. In the event you have enabled AutoPlay, it is strongly advised that it be disabled. See this tutorial and follow the instructions to disable AutoPlay if you enabled it: AutoPlay - Enable or Disable AutoRun
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Š Designer Media Ltd
All times are GMT -5. The time now is 01:34.
Find Us