Multiple Microsoft Video Control ActiveX Remote Code Execution Vulnerabilities
| Notification Type: | IBM Internet Security Systems Protection Advisory |
| Notification Date: | July 06, 2009 |
| Notification Version: | 1.5 |
| Name: | Multiple Microsoft Video Control ActiveX Remote Code Execution Vulnerabilities |
| Public disclosure/ In the wild date: |
July 6, 2009 (public disclosure) |
| Aliases: | MS09-032 and MS09-037 |
| CVE: | CVE-2008-0015 and CVE-2008-0020 |
| Description: | Multiple vulnerabilities were discovered in the Microsoft Video Controller ActiveX Library, MSVidCtl, which can result in reliable remote code execution. One of these vulnerabilities, CVE-2008-0015, has been exploited in the wild since June 11, 2009 (as discovered by X-Force) and was touted by the media and by SANS as being exploited in the wild on July 6, 2009. |
| Discoverers: | The buffer overflow vulnerability (CVE-2008-0015) was researched by Ryan Smith and Alex Wheeler of IBM X-Force. The memory corruption vulnerability (CVE-2008-0020) was researched by Robert Freeman of IBM X-Force. |
ISS Coverage |
|||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||
* The exploits that have been found in the wild (as of the publication date of this advisory) are obfuscated and, therefore, detected through one of our obfuscation signatures (JavaScript_Obfuscation_Fre). Other obfuscation signatures may also apply to in-the-wild attack attempts. Content Updates released on July 14, 2009 removed some false alarms flagged by JavaScript_Obfuscation_Fre and added the list of kill bits from the Microsoft Advisory (972890) to the HTML_IE_ActiveX_Loader_Heap_Corruption signature. Customers that have not applied this update can use the following instructions to modify this siganture to include the kill bits themselves: The Script_ATL_Stream_Load and HTML_ATLStream_BO signatures are designed to catch unobfuscated attack attempts. Customers can also add the ClassID that is currently being exploited (0955AC62-BF2E-4CBA-A2B9-A63F772D46CF) to the HTML_IE_ActiveX_Loader_Heap_Corruption signature to catch any unobfuscated exploit attempts by using the pam.content.clsid.activexloaderbo.blacklist='<clsid>' tuning parameter. To add more than one ClassID (for example, all of the new killbits listed in the Microsoft Advisory - see References below), use: pam.content.clsid.activexloaderbo.blacklist.1='<clsid>' |
|||||||||||||||||||||||||||||||||||||||||||||
Detailed Description |
|||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||
References |
|||||||||||||||||||||||||||||||||||||||||||||
Revision History |
|||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||
|
* According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
About IBM Security SystemsIBM Security Systems include an extensive portfolio of hardware, software solutions, professional and managed services offerings covering the spectrum of IT and business security risks: people and identity, data and information, application and process, network, server and endpoint and physical infrastructure, empowering clients to innovate and operate their businesses on the most secure infrastructure platforms. Through world-class solutions that address risk across the enterprise, IBM helps organizations build a strong security posture that helps reduce costs, improve service, and manage risk. IBM X-Force(R) Research and Development is one of the most renowned commercial security research and development groups in the world. For more information on how to address today's biggest risks, please visit us at ibm.com/security. |
|||||||||||||||||||||||||||||||||||||||||||||
