Zero-day exploit targets European website

SECURITY

-
Image: By BiztechAfrica
Zero-day exploit targets European website

Sophos is advising computer users and administrators to exercise caution following the discovery of an as-yet unpatched security vulnerability in Microsoft software.

SophosLabs determined that the website of a European aeronautical parts supplier - which is currently not being named due to the sensitivity of the situation - had been hacked, and a malicious attack planted on the website which exploits a zero-day Microsoft security vulnerability.

Sophos was alerted to the security problem when a Sophos customer attempted to visit the affected website, and received a warning message that a file on the site was infected by code which attempts to exploit a vulnerability in Microsoft XML Core Services which could allow Remote Code Execution - a vulnerability known as CVE-2012-1889 - which has been linked to recent warnings from Google about 'state-sponsored attacks'.

"One way that hackers break into large companies and organisations is to target their supply chain. Rather than try to hack a company which may have robust security practices and security teams, they can instead attack a smaller supplier who is less likely to notice the security breach," says Brett Myroff, CEO of Sophos distributor, NetXactics.

Users running any flavour of currently-supported Windows are vulnerable, from XP, up to and including Windows 7. All supported editions of Microsoft Office 2003 and Microsoft Office 2007 are also vulnerable. At the time of writing there is not yet an official patch from Microsoft - but the company recommends that Internet Explorer and Microsoft Office users immediately install a Fix it solution, downloadable with instructions from Microsoft Knowledge Base Article 2719615, until the company issues an official fix.

"Users should not underestimate the seriousness of this vulnerability. It's being actively exploited in the wild, and there is currently no patch available for it.

“Sophos has raised its threat level rating to 'Critical'. Sophos does provide protection against the exploit - but the best solution of all would be to have a proper fix from Microsoft,” Myroff says.

 

 



Share the News

Get Daily Newsletter

comments powered by Disqus

MORE SECURITY NEWS

Endpoints the new perimeter

Jayson O’Reilly, director of sales and innovation at DRS, says the vectors through which cyber criminals attack have changed, moving from infrastructure, to the user themselves and the endpoint. Read More

Benin’s internet cafés become headquarters for cybercrime

Internet cafés in the West African nation of Benin appear to be fast becoming ‘command centres’ for online scammers. Read More

Heartbleed a ‘severe vulnerability’

Today will be a memorable one in cybersecurity history, thanks to the end of Windows XP support and the coming to light of the Heartbleed Open SSL vulnerability, says Lucas Zaichkowsky, Enterprise Defense Architect at AccessData. Read More

Kaspersky Lab Launches worldwide interactive cyberthreat map

Kaspersky Lab has launched an interactive cyberthreat map that visualises cyber security incidents occurring worldwide in real time.  Read More

Kaspersky Lab study: about one third of all phishing attacks aimed at stealing money

Cybercriminals are trying harder than ever to acquire confidential user information and steal money from bank accounts, says a new study by Kaspersky Lab. Read More

Uganda to host Banking Fraud and ICT Security Conference

The 3rd Annual East Africa Banking and ICT Security Summit will be held on April 25 in Kampala Uganda. Read More

Kenya’s cyber security strategy enters homestretch

Kenya is putting in place a cyber security strategy to protect the country’s online assets. Read More

Over the NSA surveillance hype? Here’s why you shouldn’t be

A year after the Snowden revelations, the panic has died down and most companies and individuals are carrying on as they did before. But they shouldn’t be, says JJ Milner, MD of Global Micro. Read More

Three layers of security: crucial for business

Businesses today need to focus equally on physical, personnel and cyber security in order to mitigate risk in the face of growing criminal focus on enterprise data, says UK-based security expert Chris Phillips. Read More

2014 Banking and ICT summits pegged for Uganda, Zambia and Ethiopia

Cyber Security Africa has announced that its 2014 Banking and ICT summits will be hosted in Uganda, Zambia and Ethiopia.  Read More

PRESS OFFICES

Sage ERP AfricaSage Pastel AccountingTrust PayVMWareSamsung ElectronicsMitsumi DistributionPhoenix DistributionSage HR AfricaMTN Business

FEATURED STORY

Kenyan shift to Green Economy would generate USD 45bn by 2030 Kenyan shift to Green Economy would generate USD 45bn by 2030

Kenya’s transition to a green economy could produce major economic benefits  equivalent to an estimated USD 45 billion by 2030, a new  study shows.

IN DEPTH

E-waste threatens Ghana’s beachesE-waste threatens Ghana’s beaches

Many beaches in Ghana, already stressed by pollution and poor maintenance, are now facing a new threat: e-waste.

COMPANY NEWS

VMware Reports First Quarter 2014 Results

VMWare has announced Year-over-Year revenue growth of 14% to $1.36 Billion in its Q114 results.