Printed from http://www.electronista.com

Microsoft puts out Duqu malware workaround, vows a fix

updated 04:45 pm EDT, Fri November 4, 2011

Exploit could wreck files or alter permissions

Microsoft has confirmed a vulnerability in the Windows kernel that was being used in the Duqu exploit. If used, an attacker could install apps, change data, or create new accounts with full user rights. Microsoft is working on a full fix, and in the meantime, is offering a workaround for download (free, Fix it tool).

The threat takes advantage of a vulnerability in Microsoft Windows' Win32k TrueType font parsing engine, and lets a hacker run arbitrary code in kernel mode, the deepest level of access.

The workaround does have possible negative side effects. It could prevent apps that rely on embedded True Type fonts, such as Office documents, browsers and document viewers, from rendering text properly.

Although the threat is real, and there have been instances of computers being exploited, Microsoft said there was "low customer impact at this time." The malware is usually spread through e-mail attachments, but cannot be exploited automatically through the e-mail itself. For an attack to be successful, a user has to open an infected attachment.

Microsoft has not said when a full fix would be available. It could come as soon as next Tuesday with its regular update schedule. It could wait until next month, or it could make it available sooner through a special update. The Windows developer often puts out updates if it believes there's a major threat from a zero-day exploit. [via Sophos]



By Electronista Staff
Post tools:

TAGS :

toggle

Comments

Login Here

Not a member of the MacNN forums? Register now for free.

toggle

Network Headlines

Follow us on Facebook

toggle

Most Popular

Advertisement

Recent Reviews

Prong PWR Case

Ultimately there's one thing we all want from smartphone accessories; we want options. When it comes to keeping our iPhone charged, we ...

iHome iBT74 Color Changing Bluetooth Speaker

There's no reason why your tech can't look good while doing what it was designed to do. That's the reason that sports cars look good a ...

Logitech Gaming Daedalus Prime Mouse

Logitech Gaming continues to expand upon its peripherals line, with each one looking to fit neatly into a breadth of gaming needs. Bui ...

Advertisement

toggle

Most Commented