Microsoft is having quite a week. The company is seeing reports of vulnerabilities before Patch Tuesday, fixing data-corruption issues, and getting flooded with visitors trying to download the beta version of Windows 7.
First up, security. If you didn’t patch for the Microsoft Windows Server RPC Handling Remote Code Execution Vulnerability last year, you could be targeted this year through a vulnerability that can be spread through USB ports.
Security researchers are warning of a worm dubbed Downadup. It appeared on Dec. 30 and can not only propagate by exploiting the vulnerability, but also by infected USB sticks and by exploiting weak passwords, according to Symantec.
The W32.Spybot, W32.Randex, and W32.Mytob variants all used almost identical methods to spread, the company said, but the new variant requires more effort to protect corporate networks.
Automatic Execution
“W32.Downadup.B creates an autorun.inf file on all mapped drives so that the threat automatically executes when the drive is accessed. The threat then monitors for drives that are connected to the compromised computer in order to create an autorun.inf file as soon as the drive becomes accessible,” Symantec Security Response wrote on the company’s blog on Friday.
The worm also monitors DNS requests to domains containing certain strings, and blocks access to those domains so it will appear that the network request timed out. According to Symantec, this means infected users may not be able to update their security software from those Web sites. That’s a problem, the company warned, because worm authors generally dish out new variants constantly.
Symantec said it’s seeing considerable detections of both variants of W32.Downadup and W32.Downadup.B. The infections are geographically widespread, with the highest infection rates typically in countries with high rates of computer and Internet usage.
“DownAdUp is reportedly getting worse in parts of Europe and Asia. We expect this worm family…