Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Windows 0-day exploit found on Web
Robert Lemos, 2005-12-28
Comments Mode:
Windows 0-day exploit found on Web 2005-12-29
Psuedo-Anonymous Coward
The 0-day WMF vulnerability does not gain an exploiter System priviliges.

http://www.microsoft.com/technet/security/advisory/912840.mspx...

[ more ]  [ reply ]
Windows 0-day exploit found on Web 2005-12-29
TJONES (1 replies)
I don't know what the previous poster's definition of "system priviliges" is, but Microsoft's advisory specifically says "An attacker who successfully exploited this vulnerability could take complete control of the affected system."...

[ more ]  [ reply ]
Re: Windows 0-day exploit found on Web 2005-12-29
Matthew Murphy (1 replies)
Yes, in the event you're running all tasks as an administrative user, that's true. If you're logged in as a non-admin, the attack grants the web site non-administrative privileges. It is all relative to the level of privilege you hold when your system is attacked. This is true of 99.99% of client...

[ more ]  [ reply ]
Re: Re: Windows 0-day exploit found on Web 2006-01-03
Anonymous
Meanwhile, on my Macs and my UNIX boxes, I run without root privileges and there's no pain at all involved....

[ more ]  [ reply ]
Windows 0-day exploit found on Web 2005-12-29
Matthew Murphy
The article should clarify that the release from Microsoft is an advisory release, not a bulletin. A bulletin is a specific type of alert used to distribute patches....

[ more ]  [ reply ]
Windows 0-day exploit found on Web 2005-12-29
Matthew Murphy
The article should clarify that the release from Microsoft is an advisory release, not a bulletin. A bulletin is a specific type of alert used to distribute patches....

[ more ]  [ reply ]
Windows 0-day exploit found on Web 2005-12-30
Allen
If Microsoft, well know for soft-pedaling risks, says: "What might an attacker use the vulnerability to do?

An attacker who successfully exploited this vulnerability could take complete control of the affected system." then you know it truly is dangerous.

Mr. Pseudo-Anonymous needs to read all...

[ more ]  [ reply ]
micromonkeys 2005-12-30
assurbanipal (2 replies)
(quote from article)

"Microsoft has created a network of automated Windows systems, known as honeymonkeys, that browse the Web to find malicious code targeted at Internet Explorer."

...they'd better spend their bucks sharpening the coding skills of their IE dev-monkeys instead.

micro$oft should b...

[ more ]  [ reply ]
Re: micromonkeys 2005-12-31
Anonymous
It's not in IE; it's in an image-parsing dll....

[ more ]  [ reply ]
Re: micromonkeys 2006-01-02
atomcodedestroyer (1 replies)
Unix, Linux, Mac's Tiger OS Operatings systems fair no better than Microsoft windows operatings systems,

Linux can be infilterated in less than 4 seconds across the internet and many Linux's machines have badly writtern codes themselves that bring unlimited problems during installation and usage ...

[ more ]  [ reply ]
I call Astroturf! 2006-01-03
Anonymous
"Unix, Linux, Mac's Tiger OS Operatings systems fair no better than Microsoft windows operatings systems,"

I call Astroturf.

The tight integration between Internet Explorer, Windows Explorer, Outlook, ActiveX, and the HTML control has been cause for exploit after exploit for the past seven yea...

[ more ]  [ reply ]
Windows 0-day exploit found on Web 2005-12-30
Anonymous
Considering that a majority of people have their local machine accounts in the admin group, I think its logical for any exploit to be crafted around the assumption that they will have full system access....

[ more ]  [ reply ]
Windows 0-day exploit found on Web 2005-12-30
Anonymous (1 replies)
Well - Microsoft does it again. Why should "any browser" show WMF files without installed plug-in? IrfanView does a good job for me.

...

[ more ]  [ reply ]
Re: Windows 0-day exploit found on Web 2005-12-30
Anonymous (1 replies)
The real question should be why does a rendering engine execute code? And why are there no bounds or sanity checks performed on it? A shining example of trying to hat trick a release and cutting corners as opposed to QA. Slow and steady wins the race. Though even without time constraints doesn't gua...

[ more ]  [ reply ]
Re: Re: Windows 0-day exploit found on Web 2006-01-04
Anonymous
Microsoft OS has more problems than simple

rendering engine exploits. Windows OS from base

up is flawed. Microsoft will not adopt a

system of sanity checks, untill they develope

a Higher Language, simply because, why pay for

developement when software can doit, I find the

old world at work eve...

[ more ]  [ reply ]
Windows 0-day exploit found on Web 2006-11-15
Anonymous
Yes i got the exploit and there was no way to get it off my machine. i tried all types of antvirus and antispyware but to no avail. had to reload windows xp. it left my machine without a font folder and no access to help and support. nasty one. all characters were in a strange code making it impossi...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus