Zero-day exploit targets European website
SECURITYBy BiztechAfrica - June 22, 2012, 10:02 a.m.
Sophos is advising computer users and administrators to exercise caution following the discovery of an as-yet unpatched security vulnerability in Microsoft software.
SophosLabs determined that the website of a European aeronautical parts supplier - which is currently not being named due to the sensitivity of the situation - had been hacked, and a malicious attack planted on the website which exploits a zero-day Microsoft security vulnerability.
Sophos was alerted to the security problem when a Sophos customer attempted to visit the affected website, and received a warning message that a file on the site was infected by code which attempts to exploit a vulnerability in Microsoft XML Core Services which could allow Remote Code Execution - a vulnerability known as CVE-2012-1889 - which has been linked to recent warnings from Google about 'state-sponsored attacks'.
"One way that hackers break into large companies and organisations is to target their supply chain. Rather than try to hack a company which may have robust security practices and security teams, they can instead attack a smaller supplier who is less likely to notice the security breach," says Brett Myroff, CEO of Sophos distributor, NetXactics.
Users running any flavour of currently-supported Windows are vulnerable, from XP, up to and including Windows 7. All supported editions of Microsoft Office 2003 and Microsoft Office 2007 are also vulnerable. At the time of writing there is not yet an official patch from Microsoft - but the company recommends that Internet Explorer and Microsoft Office users immediately install a Fix it solution, downloadable with instructions from Microsoft Knowledge Base Article 2719615, until the company issues an official fix.
"Users should not underestimate the seriousness of this vulnerability. It's being actively exploited in the wild, and there is currently no patch available for it.
“Sophos has raised its threat level rating to 'Critical'. Sophos does provide protection against the exploit - but the best solution of all would be to have a proper fix from Microsoft,” Myroff says.
MORE SECURITY NEWS
Corporate cyber security threats of the year91% of organisations polled suffered a cyber-attack at least once in the past year, says Kaspersky Lab in its security review of 2013. Read More
Managed security services grows in EMEAThe managed security services market in EMEA is experiencing rapid growth as the proliferation of targeted cyber attacks compel organisations to turn to MSS providers for their security needs, says Frost & Sullivan. Read More
Expert predicts ‘doom’ for corporate GhanaA cybercrime expert has warned that urgent steps must be taken to address the ‘incessant cybercrimes' impacting corporates in Ghana. Read More
Q3 2013 sees alarming growth in data threatsThe third quarter of 2013 was a turning point for malware writers specialising in mobile platforms, says Kaspersky Lab. Read More
Fortinet illustrates need for real world firewall testingSecurity solutions firm Fortinet has illustrated the significant difference in performance achieved by various Next Generation Firewalls under real world conditions. Read More
Cyber Security Africa to host the 2nd East Africa IT & Cyber Security ConventionAfter the success of the inaugural East Africa IT & Cyber Security Convention last year, the global event series for heads of ICT and security enters its second year. Read More
New guidelines for securing card dataThe international PCI Security Standards Council (PCI SSC) has published version 3.0 of the PCI Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS). Read More
ARM, NetClean partner to stop child abuse contentSpecialist security distributor African Risk Mitigation (ARM) has partnered with NetClean in the fight against the proliferation of child sexual abuse images across Africa. Read More
Have you been breached?Given that recent research has revealed that the average advanced persistent threat lurks on a business network for hundreds of days before it is discovered, how do businesses tell that their network has been compromised? Read More
FEATURED STORYGaming app introduces investors to trading
A new virtual stock market app is equipping would-be investors with the skills they need to trade.
BEST READ NEWS
IN DEPTHCorporate cyber security threats of the year
91% of organisations polled suffered a cyber-attack at least once in the past year, says Kaspersky Lab in its security review of 2013.