HostGator

Hackers picking on Windows Media Player exploit







<!– Sign up for our Newsletters | –>
Sign up for our Newsletters |  
Email the Editor  | 
Print 

Security researchers from antivirus vendor Trend Micro have come across a Web-based attack that exploits a known vulnerability in Windows Media Player.

“Earlier today, we encountered a malware that exploits a recently (and publicly) disclosed vulnerability, the MIDI Remote Code Execution Vulnerability (CVE-2012-0003),” Trend Micro threat response engineer Roland Dela Paz said in a blog post on Thursday.

The security flaw can be exploited by tricking the victim into opening a specially crafted MIDI (Musical Instrument Digital Interface) file in Windows Media Player.

Microsoft released a security fix for it on Jan. 10, as part of its monthly patch cycle. “An attacker who successfully exploited this vulnerability could take complete control of an affected system,” the company said at the time.

The so-called drive-by-download attack identified by Trend Micro researchers uses a malicious HTML page to load the malformed MIDI file as an embedded object for the Windows Media Player browser plug-in.

If successful, the exploit downloads and executes a computer Trojan on the targeted system, which Trend Micro detects as TROJ_DLOAD.QYUA. “We’re still conducting further analysis on TROJ_DLOAD.QYUA, but so far we’ve been seeing some serious payload, including rootkit capabilities,” Dela Paz said.

It’s not yet clear how victims are being tricked into visiting the malicious page, but the attack doesn’t appear to target a particular organization or group of people, said David Sancho, a senior antivirus researcher at Trend Micro.

According to the researcher, the attack is not widespread at the moment, but it is possible that other attackers will start exploiting the same vulnerability in the near future. “As mentioned, this is a publicly disclosed vulnerability

.... end of excerpt
Article Source: http://www.itbusiness.ca/it/client/en/home/News.asp?id=65846

This entry was posted in Stop Spam and tagged . Bookmark the permalink.

Comments are closed.