Exploits of MS05-038 in the wild

Printer-friendlyE-mail this news to a friendYour comment

Websense Security Labs(TM) has detected malicious websites that are exploiting the recently reported MS05-038 vulnerability (see the following article on the Microsoft website at: http://www.microsoft.com/technet/security/Bulletin/MS05-038.mspx).

Successful exploitation of this vulnerability allows the attacker to execute code of their choice on the workstation. At this time, malicious websites have been observed to exploit this vulnerability by downloading and running code on the end-user's machine.

The example site we have included below is hosted in Sweden, was up at the time of this alert, and is registered with fraudulent information. The site appears to be posing as a pharmaceutical website, which is becoming more commonplace. The attackers send out millions of SPAMS for a variety of miracle medical wonders and direct you to a fraudulent website in order to purchase them. Several cases of these have been found to be fraudulent sites that are capturing personal information for the purpose of identify theft and, in this case, are attempting to exploit systems though a new vulnerability within the browser.

The below site had encoded JavaScript at the bottom of the page that attempts to exploit the CLASSID: 4EFE2452-168A-11D1-BC76-00C04FB9453B (devenum.dll) vulnerable object in order to run shell code on the machine. Users who visit this site and do not have the patched version of Microsoft Internet Explorer will have their browser crash, as the implementation of the shell code within the site appears to be faulty. However, if the code was correctly entered, unprivileged access of the system could occur without user-intervention.

We expect to see additional exploits of MS05-038 in the near future, as it is very new and allows privileged access to the machine.

17.08.2005, Websense




Comments on this news 


Write your comment on this news

Subscribe to the newsletter

Never miss a story and stay informed with our newsletter.
Your email:  
RSS-Feed: All current newsOur News on your website

More current news

VASCO gives an answer to security concerns when deploying Software as a Service (SaaS)
Making penetration testing work
Double trouble, as new Facebook worm targets Google Reader
Wipro and Fortify Software Form Partnership to Assure the Security of Client Software Worldwide
VASCO launches PKI-based authentication solution

News on other topics

SharePartXXL has released Version 2.0 of the Taxonomy Extension for WSS/MOSS
RTL, VOX and SUPER RTL operate communication portals with CONTENS
Finally: A professional Open Source Digital Asset Management (DAM)
Pentland selects FirstSpirit for global web content management
ContentServ has successfully extended its International Partner Network in 2008

Veranstaltungen
The Content Management PortalThe Document Management PortalThe IT Security PortalThe Customer Relationship Management PortalThe E-Commerce PortalThe Enterprise Resource Planning PortalPortal on VoIP and mobile communication The directory of Clinic IT SolutionsThe directory for IT professionals
homeimprintprivacy policycontactadvertising

know how

news

events

security alerts

Quick search




Recommend us


Do you like our website? Why not recommend us?



Recommended reading


Understanding Digital Signatures