Microsoft on Tuesday released four security updates to fix flaws in Windows XP, Windows 7, and Microsoft Office. Three of the security bulletins are rated critical and the fourth is rated important.
Of the zero-day vulnerabilities patched Tuesday, Symantec is only seeing one being exploited in the wild. In just the few weeks since the Help and Support Center issue came to light, three public exploits have surfaced — all using different attack mechanisms, said Joshua Talbot, security intelligence manager for Symantec Security Response. Symantec saw attack activity increasing on June 21, but it has since leveled out.
“Microsoft didn’t rate the Outlook SMB attachment vulnerability as critical, but we think it’s likely to be exploited,” Talbot warned. “It appears fairly simple for an attacker to figure out and create an exploit for, which could cause executable file e-mail attachments, such as malware, to slip past Outlook’s list of unsafe file types. A user would still have to double-click on the attachment to open it, but if they do, the file would run without any warning.”
Talbot offered a possible scenario that could involve a targeted attack against an organization. In this scenario, he explained, a user could get a socially engineered e-mail with a malicious attachment disguised as something innocuous. Once convinced to click on the attachment, nothing would appear to happen. The user might delete the message and move on, assuming the file to be corrupted. In reality, he said, malware was secretly installed.
Mitigating E-Mail Attacks
As Oliver Lavery, director of security research and development for nCircle, sees it, July’s patches are pretty mundane. The most interesting vulnerability for the enterprise is MS10-045, which lets an attacker use a specially crafted UNC path in an Outlook attachment to bypass Outlook’s warning about opening potentially malicious attachments.
This is significant, Lavery said,…