Microsoft has rushed out a patch to correct the way Windows parses shortcuts, a vulnerability we reported two weeks ago. Hackers have been exploiting the bug, which Microsoft had warned was most likely to be spread by removable drives when AutoPlay was not disabled.
While the patch, rated critical, fixes currently supported Windows operating systems, Windows XP SP2 and Windows 2000 were not included. Those versions have reached their end of life, although many systems are still using them. The patch can be applied with the Microsoft Update and Windows Update services.
Already Being Exploited
In mid-July, Microsoft admitted vulnerability was being exploited by the Stuxnet worm. That virus targets industrial control systems usually referred to as supervisory control and data-acquisition systems, or SCADA. On Friday, Microsoft said Sality malware was also using the vulnerability.
While Windows 7 automatically disables AutoPlay for removable drives, Microsoft had suggested a workaround of disabling icons for shortcuts, which could create problems in a visual user interface. Microsoft had also suggested disabling the WebClient service used by WebDAV, but that hampered SharePoint users.
Microsoft’s MS-10-046 bulletin says the problem was fixed by “correctly validating the icon reference of a shortcut.” The software giant advised users to undo the workaround of disabling shortcuts after the patch, but some web posts advised that step needs to be taken before the shortcut is applied.
The patch creates a new version of Shell32.dll, a crucial Windows library file. If incorrectly updated on some machines, some PCs could lock up.
All Supported Windows Versions
Chester Wisniewski of the Sophos security firm said the vulnerability involves how Shell32.dll attempts to load control-panel icons from applets. If a specially made shortcut points to a malicious file, Windows Explorer will execute it simply by browsing to the location.
The shortcut vulnerability affects all currently supported Windows versions. These include XP…