New post on *WatchGuard Security Center*


<http://watchguardsecuritycenter.com/author/coreynach/>
*UPDATE TO: Advanced Attackers Exploit IE 0day in the
Wild*<http://watchguardsecuritycenter.com/2014/05/01/update-to-advanced-attackers-exploit-ie-0day-in-the-wild/>

by *Corey Nachreiner*<http://watchguardsecuritycenter.com/author/coreynach/>
Severity: High Summary:

·         *This vulnerability affects:* All versions of Internet Explorer
(IE)

·         *How an attacker exploits it:* By enticing a user to visit web
site containing malicious content

·         *Impact:* An attacker can execute code with your privileges,
potentially gaining complete control of your computer

·         *What to do:* Install Microsoft's emergency IE patch immediately,
or let Windows Update do it for you
Exposure:

On Monday, we released *an
alert*<http://watchguardsecuritycenter.com/2014/04/28/advanced-attackers-exploit-ie-flash-0days-in-the-wild/>
warning
about a zero day vulnerability affecting all version of Internet Explorer.
Researchers discovered attackers exploiting this critical flaw in the wild,
and Microsoft had not yet released a patch at that time.

Today, Microsoft released an *out-of-cycle security
bulletin*<https://technet.microsoft.com/en-US/library/security/MS14-021>containing
an update to fix this serious vulnerability. As mentioned in our
original alert, IE suffers from something called a "*use after
free*<https://www.owasp.org/index.php/Using_freed_memory>"
memory corruption vulnerability. By enticing one of your users to a web
site containing malicious content, an attacker can exploit this flaw to
execute code on your machine, with your privileges. As usual, if you have
local administrator privileges, the attacker gains full control of your
machine.

Keep in mind, today’s attackers often hijack *legitimate *web pages and
booby-trap them with malicious code. Typically, they do this via hosted web
ads or through *SQL injection* <http://en.wikipedia.org/wiki/Sql_injection>
 and *cross-site scripting
(XSS)*<http://www.watchguard.com/glossary/c.asp#XSS> attacks.
Even recognizable and authentic websites could pose a risk to your users if
hijacked in this way, and the vulnerabilities described in today’s bulletin
are perfect for use in drive-by download attacks. Furthermore, attackers
are already exploiting this particular flaw in targeted attacks. We highly
recommend you install Microsoft's IE update immediately

We have included the original
*alert*<http://watchguardsecuritycenter.com/2014/04/28/advanced-attackers-exploit-ie-flash-0days-in-the-wild/>
below
for your convenience.
Solution Path:

Microsoft has released IE updates to correct this vulnerability. You should
download, test, and deploy the updates immediately, or let Windows Update
do it for you. You can find the updates in the “*Affected and Non-Affected
Software* <https://technet.microsoft.com/library/security/ms14-021#ID0EYC>”
section of *Microsoft’s IE
bulletin*<https://technet.microsoft.com/library/security/ms14-021>.
*Also note, Microsoft has included updates for Windows XP customers,
despite their End-of-Life date last month**.*

If for some reason you cannot patch immediately, there are also some
workarounds than can mitigate the issue. We detail those workarounds in
our original 
*alert*<http://watchguardsecuritycenter.com/2014/04/28/advanced-attackers-exploit-ie-flash-0days-in-the-wild/>,
which we've included below for your convenience.
For All WatchGuard Users:

As mentioned in our original
*alert*<http://watchguardsecuritycenter.com/2014/04/28/advanced-attackers-exploit-ie-flash-0days-in-the-wild/>,
there are a number of things WatchGuard XTM customers can do to protect
themselves. For instance, you can use our proxy policies to block Flash
content by extension (.SWF) or by MIME type
(application/x-shockwave-flash). Furthermore, our IPS service includes
signatures that block this IE exploit (update to signature set v4.408).
Nonetheless, we still highly recommend you install Microsoft's IE update to
completely protect yourself from this attack.
Status:

Microsoft has released patches to fix this vulnerability.
References:

·         *MS Security Bulletin
MS14-021*<https://technet.microsoft.com/en-US/library/security/MS14-021>

This alert was researched and written by *Corey Nachreiner, CISSP
<http://www.watchguard.com/corporate-info/speakers-bureau.asp#corey>* (
*@SecAdept* <http://twitter.com/SecAdept>).
------------------------------

Over the weekend, Microsoft released a critical *security
advisory*<https://technet.microsoft.com/en-US/library/security/2963983>warning
customers of a serious new zero day vulnerability in Internet
Explorer (IE), which attackers are exploiting in the wild. Around the same
time, Kaspersky also noted an attack campaign leveraging a new Adobe Flash
zero day flaw, which *Adobe patched
today*<http://helpx.adobe.com/security/products/flash-player/apsb14-13.html>.
I'll
discuss both issues below, starting with the IE issue.
IE Zero Day in the Wild

According to this *blog
post*<http://www.fireeye.com/blog/uncategorized/2014/04/new-zero-day-exploit-targeting-internet-explorer-versions-9-through-11-identified-in-targeted-attacks.html>,
researchers
at FireEye discovered advanced attackers exploiting this zero day IE flaw
as part of a persistent attack campaign they are calling "Operation
Clandestine Fox." The attack targets IE 9-11 and also leverages a Flash
flaw to help bypass some of Windows' security features.

Shortly after FireEye's post, Microsoft released a *security
advisory*<https://technet.microsoft.com/en-US/library/security/2963983>confirming
the previously undiscovered flaw in IE. The advisory warns that
the flaw affects all versions of IE (though the attack seems to target IE
9-11). While Microsoft is still researching the issue, the vulnerability
seems to be a "*use after
free"*<https://www.owasp.org/index.php/Using_freed_memory>class of
memory corruption vulnerability. In short, if an attacker can
entice you to a web page containing maliciously crafted content, he could
exploit this flaw to execute code on your machine, with your privileges. As
usual, if you have local administrator privileges, the attacker would gain
full control of your machine. It's interesting to note, the attackers also
leverage a known Adobe Flash issue to help defeat some of Microsoft's
Windows memory protection features.

Zero day IE vulnerabilities are relatively rare, and very dangerous.
Attackers are already exploiting this IE one in the wild, so it poses a
significant risk. Unfortunately, Microsoft just learned of the flaw, so
they haven't had time to patch it yet. I suspect Microsoft will release an
out-of-cycle patch for this flaw very shortly since this is a high-profile
issue. In the meantime here a few workarounds to help mitigate the flaw:

·         *Temporarily use a different web browser* - I'm typically not one
to recommend one web browser over another, as far as security is concerned.
They all have had vulnerabilities. However, this is a fairly serious issue.
 So you may want to consider temporarily using a different browser until
Microsoft patches.

·         *Install Microsoft EMET* -
*EMET*<http://blogs.technet.com/b/srd/archive/2012/05/15/introducing-emet-v3.aspx>is
an optional Microsoft tool that adds additional memory protections to
Windows. I described EMET in a previous *episode of WatchGuard Security
Week in 
Review*<http://watchguardsecuritycenter.com/2012/06/22/watchguard-security-week-in-review-episode-23/>.
Installing EMET could help protect your computer from many types of memory
corruption flaws, including this one. This *Microsoft blog
post*<http://blogs.technet.com/b/srd/archive/2014/04/26/more-details-about-security-advisory-2963983-ie-0day.aspx>
shares more
details on how it can help with this issue.

·         *Configure Enhanced Security Configuration mode on Windows
Servers* - Windows Servers in *Enhanced Security
Configuration*<http://technet.microsoft.com/library/dd883248.aspx>mode
are not vulnerable to many browser-based attacks.

·         *Disable VML in IE* - This exploit seems to rely on VML to work.
Microsoft released a *blog
post*<http://blogs.technet.com/b/srd/archive/2014/04/26/more-details-about-security-advisory-2963983-ie-0day.aspx>
detailing
how disabling VML in IE, or running IE in "Enhanced Protection Mode" can
help.

·         *Make sure your AV and IPS is up to date* - While not all IPS and
AV systems have signatures for all these attacks yet, they will in the
coming days. In fact, *WatchGuard's IPS engineers have already created
signatures to catch this attack. We are QA testing the signatures now, but
they should be available to XTM devices shortly**.* Whatever IPS system you
use, be sure to keep your AV and IPS systems updating regularly, to get the
latest protections.

·         *WatchGuard XTM customers can block Flash with proxies* - If you
own a WatchGuard XTM security appliance, you can use our proxy policies to
block certain content, including Flash content. For instance, you can use
our SMTP or HTTP proxies to block SWF files by extensions (.SWF) or by MIME
type (application/x-shockwave-flash). Keep in mind, blocking Flash blocks
both legitimate and malicious content. So only implement this workaround if
you are ok with your users not accessing normal Flash pages.

*Adobe Patches Flash Zero Day*

Coincidentally, Adobe also released *an emergency Flash
update*<http://helpx.adobe.com/security/products/flash-player/apsb14-13.html>today
fixing a zero day exploit that other advanced attackers are also
exploiting in a targeted watering hole campaign. The patch fixes a single
vulnerability in the popular Flash media player, which attackers could
exploit to run arbitrary code on your system; simply by enticing you to a
web site containing specially crafted Flash content. This exploit was
discovered in the wild by Kaspersky researchers (one of our security
partners). According to *Kaspersky's
research*<https://www.securelist.com/en/blog/8212/New_Flash_Player_0_day_CVE_2014_0515_used_in_watering_hole_attacks>,
the exploit was discovered on a Syrian website, and seems to be designed to
target potential Syrian dissidents.

The good news is there is a patch for this flaw. So if you use Adobe Flash, *go
get the latest update now* <http://get.adobe.com/flashplayer/>. By the way,
some browsers like Chrome and IE 11 embed Flash directly, so you will also
have to update those browsers individually. Finally, though the IE zero day
I mentioned earlier does rely on a Flash issue, this particular zero day
Flash flaw is totally unrelated. One additional note; WatchGuard's IPS
engineers have also created a signature for this exploit as well. It will
be available shortly, once testing is complete.

So to summarize, if you use IE, disable VML, install EMET, and watch for an
upcoming patch. If you use Flash, updates as soon as you can. I will be
sure to inform you here, as soon as Microsoft releases their real patch or
FixIt. — *Corey Nachreiner, CISSP
<http://www.watchguard.com/archive/bios.asp>*
(*@SecAdept*<http://twitter.com/SecAdept>
)

*Corey Nachreiner
<http://watchguardsecuritycenter.com/author/coreynach/>*| May 1, 2014
at 11:04 am | Tags:
*0day* <http://watchguardsecuritycenter.com/?tag=0day>,
*exploit*<http://watchguardsecuritycenter.com/?tag=exploit>,
*flash* <http://watchguardsecuritycenter.com/?tag=flash>,
*ie*<http://watchguardsecuritycenter.com/?tag=ie>,
*internet explorer*<http://watchguardsecuritycenter.com/?tag=internet-explorer>,
*kaspersky* <http://watchguardsecuritycenter.com/?tag=kaspersky>, *memory
corruption* <http://watchguardsecuritycenter.com/?tag=memory-corruption>,
*remote
code execution*<http://watchguardsecuritycenter.com/?tag=remote-code-execution>,
*use after free* <http://watchguardsecuritycenter.com/?tag=use-after-free>,
*zeroday* <http://watchguardsecuritycenter.com/?tag=zeroday> |
Categories: *Security
Updates* <http://watchguardsecuritycenter.com/?cat=3125> | URL:
*http://wp.me/pVP8E-1lf* <http://wp.me/pVP8E-1lf>

Comment<http://watchguardsecuritycenter.com/2014/05/01/update-to-advanced-attackers-exploit-ie-0day-in-the-wild/#respond>

   *See all 
comments*<http://watchguardsecuritycenter.com/2014/05/01/update-to-advanced-attackers-exploit-ie-0day-in-the-wild/#comments>



*Trouble clicking?* Copy and paste this URL into your browser:
*http://watchguardsecuritycenter.com/2014/05/01/update-to-advanced-attackers-exploit-ie-0day-in-the-wild/*<http://watchguardsecuritycenter.com/2014/05/01/update-to-advanced-attackers-exploit-ie-0day-in-the-wild/>





Thanks for flying with WordPress.com <http://wordpress.com>



__._,_.___


 Visit Your 
Group<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmaTU4ZmhvBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzEzOTg5Njk4NjA->


 [image: Yahoo!
Groups]<https://groups.yahoo.com/neo;_ylc=X3oDMTJldWJ1NjFxBF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTM5ODk2OTg2MA-->
• Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe <[email protected]?subject=Unsubscribe>•
Terms
of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to