Microsoft Security Advisory (2286198)

Corrine

Account closed
Local time
5:51 PM
Messages
2,303
Location
Upstate NY
Microsoft has released Security Advisory 2286198, which addresses a publicly reported vulnerability in Windows Shell. From the Security Advisory:

"The vulnerability exists because Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the user clicks the displayed icon of a specially crafted shortcut. This vulnerability is most likely to be exploited through removable drives."
If AutoPlay is disabled, particularly for USB devices, in order for the vulnerability to be exploited, it would be necessary to manually browse to the root folder of the removable disk. AutoPlay for removable disks is automatically disabled on Windows 7. In the event you have enabled AutoPlay, it is strongly advised that it be disabled.

To disable AutoPlay the prerequisites in Microsoft KB Article 967715 must first be installed. If your computer is up-to-date, they are already installed. The KB Article also includes instructions on "How to disable the Autorun functionality in Windows".

Note that it is additionally reported on the MSRC Blog that, "In the wild, this vulnerability has been found operating in conjunction with the Stuxnet malware". For more information on Stuxnet, see the MMPC blog post. Of further interest, as the MSRC Blog reports

"signatures in up-to-date versions of Microsoft Security Essentials, Microsoft Forefront Client Security, Windows Live OneCare, the Forefront Threat Management Gateway, and the Windows Live Safety Platform protect customers against the Stuxnet malware."
References:

 

My Computer

OS
Windows 7 & Windows Vista Ultimate
This applies to

Microsoft Windows 2000
Windows XP Service Pack 2
Windows XP Service Pack 3
Windows Server 2003 Service Pack 1
Windows Server 2003 Service Pack 2

Not Win 7
 

My Computer

Computer Manufacturer/Model Number
Store Assembled
OS
Win 7
CPU
AMD Phenom™ II X6 1090T
Motherboard
ASUS M4A89GTD PRO/USB3 with AMD® 890GX/SB850 chipset
Memory
8 GB Corsair (2X4Gb)
Graphics Card(s)
Included in AMD® 890GX/SB850 chipset on MB
Sound Card
Included in AMD® 890GX/SB850 chipset on MB
Monitor(s) Displays
Dell ST 2210 21.5inch LCD
Hard Drives
Seagate Barracuda 7200.12 1TB SATA
PSU
500 W
Case
Zebronic ATX
Cooling
No extra cooling
Hi, justalogin.

AutoPlay for removable disks is automatically disabled on Windows 7. In the event you have enabled AutoPlay, it is strongly advised that it be disabled. See this tutorial and follow the instructions to disable AutoPlay if you enabled it: AutoPlay - Enable or Disable AutoRun
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Back
Top