07-06-2009 09:06 AM - edited 07-06-2009 09:13 AM
On Thursday, July 02, 2009, symantec became aware of a previously-un-known Vulnerability Affecting Microsoft Windows. This Issue Affects the msvidctl.dll Video Streaming ActiveX Control. Attackers can Exploit the Issue to Execute Arbitrary Code by Enticing a Vulnerable User to Visit a Malicious Web Site. This Issue is being Exploited in-the-Wild in Limited Attacks. Currently, we are not aware of any Patches for this Vulnerability.
Users are advised to:
- Use Caution while Accessing Un-Trusted Web Sites.
- Avoid following Web Links that Originate from Un-Known Sources.
- Consider setting the Kill-Bit on the associated C.L.S.I.D..
- Deploy Script-Blocking Mechanisms in the Browser.
- Deploy Memory-Protection Schemes such as Non-Executable Stack/Heap Configurations and Randomly-Mapped Memory Segments.
Solved! Go to Solution.
07-06-2009 12:41 PM
On Monday, July 06, 2009, Microsoft Published a Security Advisory Discussing the Issue.
Microsoft Security Advisory (972890):
Vulnerability in Microsoft Video ActiveX Control Could Allow Remote Code Execution:
http://www.microsoft.com/technet/security/advisory
__________________________________________________
Further Information is Available in the following Vulnerability Alert:
Microsoft Windows 'BDATuner.MPEG2TuneRequest.1' Object Remote Code Execution Vulnerability: http://www.securityfocus.com/bid/35558.
07-06-2009 04:02 PM - edited 07-06-2009 04:12 PM
Another Unpatched Vulnerability is Being Massively Exploited via Internet Explorer: http://www.symantec.com/connect/blogs/another-unpa
Please be advised that currently, this Un-Patched Vulnerability is being Exploited Wide-spread In-The-Wild, and is no longer being Exploited in "Limited Attacks" as stated in Message 01.
07-06-2009 10:39 PM
Upon successful exploitation, the script downloads another malware detected as WORM_KILLAV.AI. This malware disables and terminates antivirus software processes, and drops other malware on the affected system.
as if we do not already have enough problems
07-07-2009 12:25 AM
07-09-2009 03:54 PM
Microsoft Internet Explorer Unpatched Vulnerability is Here… Norton Users Never Fear!: http://community.norton.com/t5/Norton-Protection-B
07-09-2009 04:43 PM
Thanks for posting the link to the blog and thanks for covering for the questions.
Thanks,
John
07-13-2009 01:43 PM
In-the-Wild DirectX, DirectShow and QuickTime Attacks: http://community.norton.com/norton/board/message?b
07-13-2009 01:45 PM
Un-Patched Vulnerability Affecting "Office Web Components": http://community.norton.com/norton/board/message?b
07-14-2009 03:59 PM
Floating_Red wrote:In-the-Wild DirectX, DirectShow and QuickTime Attacks: http://community.norton.com/norton/board/message?b
oard.id=nis_feedback&thread.id=53902.
Microsoft Released a Security Update on Tuesday, July 14, 2009; please Click on the Web Link above for More Details.
