Unfixed Outlook & IE hole allows XP&Vista user promotion to Admin

March 31, 2007

I’d already decided not to post about this, but then learned more.  There is no fix.  No work around. I’m vulnerable and at this point, I can’t do anything about it.  Even on Vista, just pre-viewing an HTML email in Outlook 2002+ means you are vulnerable.   An that’s not just OE but the REAL Outlook used is offices everywhere.  You can’t turn off Java Script, or Active X or anything.  You don’t even crash.  Your system is just pwned…

What does MS have to say?

Microsoft is investigating new public reports of attacks exploiting a vulnerability in the way Microsoft Windows handles animated cursor (.ani) files. In order for this attack to be carried out, a user must either visit a Web site that contains a Web page that is used to exploit the vulnerability or view a specially crafted e-mail message or email attachment sent to them by an attacker. [...] Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This will include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.  Microsoft is actively monitoring this situation to keep customers informed and to provide customer guidance as necessary. - http://blogs.pcworld.com/staffblog/archives/003973.html

For Outlook, the only fix Microsoft has is “read all e-mail in plain text rather than HTML”.  I know Outlook REALLY well, but I don’t remember a setting that does that.  There’s no solution for Internet Explorer.  Basicaly any application, even ones that you might have written in Delphi that happen to have a TBrowser component in them that is allowed access to the outside world, is vulnerable.  So if you have any custom email programs you’ve written, watch out!

The basic avenue of attack  is to display a customized animated cursor.  Once you open that email or browse through that site,  they gain access to your computer.  There is no crash, it just instantly happens.  The code can then promote the Limited Access account you are using (because we all only use admin accounts when we need to… Yeah, right!) to an Adminstrator account, and then do whatever they please, from rootkits to personal webservers.  Oh! and of course don’t forget that an “animated” cursor can appear to be static. It can look exact your normal cursor. 

In the article “ Windows Zero-Day Flaw ‘Very Dangerous,’ Experts Say Bug affecting IE and Windows is potentially very damaging, and there’s no quick fix in sight. “, by Gregg Keizer of Computerworld, there are a couple of good quotes.

“This is a good exploit,” Roger Thompson, CTO of Exploit Prevention Labs

“According to Adrian Stone, an MSRC program manager, Outlook 2007 is invulnerable, as is Vista’s Windows Mail–as long as users don’t reply or forward the attacker’s messages. The SANS Institute’s testing, however, contradicted Microsoft; by SANS’ account, Outlook Express in Windows XP, Windows Mail in Vista, and Outlook 2003 in any version of Windows puts users at risk when they simply preview a malicious message. They don’t have to actually open the message to be in danger of an infection.”

“Worse, we know there are vulnerabilities that can be exploited in Vista to escalate privileges,” said Brown. “All you need is access to the system, which this [animated cursor] provides.” Once inside, said Brown, the attacker could up rights from even a safer local user to administrator privileges. “Then, all bets are off.”

UPDATE:

 It seems that eEye Digital Security is taking advantage of the situation and has release a patch if you have their 1 year free personal addtion intrusion software:

Patch Location: Download Now!
Patch Version: 1.0
Patch Source Code: View

The patch prevents the loading of any non local ani files.  Well, my intrusion software is somewhat out of date anyway.  I’ll give it a try.  I’ll let you know if this is another “Scare you till you upgrade” program that is hard to remove.

UPDATE #2: eEye Digital Security is incredible.  At first glance, it seems to be professional and high-level.  I think it is actually meant to protect your system and not scare your Aunt Martha into buying more and more additions to it.  I’m impressed.  I’m also sad to say that for the second time since 1985ish when I first got a PC clone (a Compaq Portable Plus with Compaq Dos 2.12 and 10mb HD, if you must know), I actually had a virus detected on any disk or computer in my home.  It was one just reported in the wild for the first time at the end of Feb.  So my current antivirus software, somewhat out of date, hadn’t picked up on it.  Still I guess 2 viruse detections out of all of the stuff I’ve done and all the disks I’ve used and stuff I’ve downloaded, is a pretty good safety record for 2.2 decades.

Share and Enjoy:
  • del.icio.us
  • Fark
  • Reddit
  • Digg
  • DZone
  • email
  • Facebook
  • FriendFeed
  • Google Bookmarks
  • Netvibes
  • Ping.fm
  • Posterous
  • Slashdot
  • StumbleUpon
  • Suggest to Techmeme via Twitter
  • Technorati
  • Tumblr
  • Yahoo! Bookmarks
  • Add to favorites
  • Blogosphere News
  • HackerNews
  • Identi.ca
  • LinkedIn
  • MySpace
  • Print
  • Yahoo! Buzz

Comments

6 Responses to “Unfixed Outlook & IE hole allows XP&Vista user promotion to Admin”

  1. David Keith on April 2nd, 2007 10:56 am

    Wow! It amazes me that after all of these years folks are still using these products. Have you tried Mozilla Firefox? How about Mozilla Thunderbird? These products are stable, mature, free, secure, and cross-platform. Addicted to Exchange? Have you tried Communigate Pro? It allows Outlook addicts to connect to Communigate as if it were an Exchange Server.

    I’d recommend a fantastic email client called Evolution that has all of the features of Outlook including the ability to connect to both Exchange and GroupWise, but unfortunately the wider CodeGear community still isn’t Linux ready.

    Oh well, maybe someday. Until then you could always try an addiction counselor…

  2. Brian on April 2nd, 2007 11:54 am

    At the office, I have no choice. It is Outlook and IE. Period. End of story. No questions asked.

    I’m not going to go into the browser war in a comment especially since it gets boring and you’ ve elected concentrate on the email side of things, which I’mmuch more interested in. Besides, yes as a resposible site host, I have installed Firefox (old and new), Opera, Konquerer (my favorite), IE 6, IE7, Maxthon 1 and Maxthon 2 and they are ALL broken in different ways and when I care about how a site looks, I check them all. THEN you should talk to me about browser rants.

    Well, setting aside the “Microsoft is evil and you are stupid for running their software” arguments (NOTE: He didn’t say that folks, it’s just a generic quote) that others have made, can you convince me to run Thunderbird? Why should I switch?

    I’m more than willing to try Thunderbird if it will match my most important feature requirement: Integration and syncronization of my contact list, and calendar events across my three main machines. IF Thunderbird can allow my PDA to have all of my notes, calendar events, emails, and address lists syncronized with my work computer, which then likewise syncronizes with the events and addresses with my home, I’ll switch at home. Assuming I can import thunderbird can import all of my emails and handle some basic filtering and sorting rules.

    I want to be able to add an email address at home and because my PDA is in the cradle, I want it to be brought with me to work and be there when I go to send my next email because the PDA is in the cradle there. I want to be able to fix a phone number on my PDA while I am at church and have it then make its way back to both home and work. I want to be able to type a registration key into my notes when I am working on a computer in a diffent part of the office, and carry it back without thought to my desktop. Likewise, I’d like my cell phone to be able to syncronize to the contact list as well, which mine now does.

    As far as I know, there’s no solution to allow this and I don’t have the time or inclination to write one when I have Outlook for free.

    > Until then you could always try an addiction counselor…
    I’ve shown my required feature set and that I’m not just following the latest turn made by the stampeding masses. Can you do the same? Hmmm? Is that a “Moooo” I herd?

    (* Yes, folks that was a pun not a typo ;) *)

    This isn’t an attack David, please don’t read it as one. But /you/ threw down the guantlet… Shall I simply pass it by? ;)

    (Oh, look at me getting all old school and forgetting about the italics/emphasis button can be used on the word you.)

  3. David Keith on April 2nd, 2007 12:56 pm

    I’m not going to go into the browser war in a comment especially since it gets boring and you’ ve elected concentrate on the email side of things, which I’mmuch more interested in. Besides, yes as a resposible site host, I have installed Firefox (old and new), Opera, Konquerer (my favorite), IE 6, IE7, Maxthon 1 and Maxthon 2 and they are ALL broken in different ways and when I care about how a site looks, I check them all. THEN you should talk to me about browser rants.

    Congratulations. You’re one of the few Codegear geeks I’ve corresponded with who are aware that there is life beyond IE. I had no intention of starting a browser ‘flame war’. It’s simply that I find too few people in our community look at browser selection from a perspective of security/functionality/flexibility, and what’s even worse is that it seems that the majority of the community is actually coding their web apps to be dependent on a single browser and platform, as if that’s all there is ever going to be.

    Having previously read your credentials, I guess I gave you too much credit for understanding the importance/critical nature of this issue.

    Well, setting aside the “Microsoft is evil and you are stupid for running their software” arguments (NOTE: He didn’t say that folks, it’s just a generic quote)…

    Strange that you brought this perspective into the discussion… I have found over the years (almost as many as you) that the only time you hear this type of statement being brought forth is when you have a Windows junkie on the defense who doesn’t realize that the word ‘enterprise’ in our professional context means something other than the latest server version from Microsoft.

    To respond, this will probably shock you, but there actually are other types of software running in corporate IT. Enterprise, by it’s very nature implies blends of hardware and software from multiple vendors, as it still isn’t feasible to meet all enterprise IT requirements running just one brand. Nothing said about evil, just the reality that makes up the crazy world of enterprise computing. It seems that this well known fact still escapes much of the BorGear crowd…

    my most important feature requirement: Integration and syncronization of my contact list, and calendar events across my three main machines. IF Thunderbird can allow my PDA to have all of my notes, calendar events, emails, and address lists syncronized with my work computer, which then likewise syncronizes with the events and addresses with my home…

    You do present some very special requirements for an email client, I did not realize that your needs were so complex. I know that thunderbird has a plugin architecture for which various developers have produced contact synchronization plugins. I don’t think they are as numerous in their support of diverse devices as Microsoft can afford to be; for example you can sync with a palm using PalmSync and HotSync, but this probably wouldn’t be sufficient for your advanced requirements. I wouldn’t however assume that just because one vendor’s software can do this that all other email client vendors can’t do this.

    I was a long time, dedicated Outlook user for many years. I gave it up years ago when, while at an Cisco IP Telephony trade show I had to return to work because the national email network – which covered all of the principal compass points in the country – was shut down because some 17 year old kid in the Phillipines wrote and emailed a VB Script that Outlook happily propagated across exchange servers world wide and cost businesses approximately $1 Billion in a 24-hour period.

    Whatever happened to critical thinking in the areas of enterprise security planning?

  4. Brian on April 2nd, 2007 3:27 pm

    Congratulations. You’re one of the few Codegear geeks I’ve corresponded with who are aware that there is life beyond IE. I had no intention of starting a browser ‘flame war’. It’s simply that I find too few people in our community look at browser selection from a perspective of security/functionality/flexibility, and what’s even worse is that it seems that the majority of the community is actually coding their web apps to be dependent on a single browser and platform, as if that’s all there is ever going to be.

    Having previously read your credentials, I guess I gave you too much credit for understanding the importance/critical nature of this issue.

    ooo butter and a barb! Very nice! (And that was a lower case b in barb… This isn’t THAT kind of a website.)

    Actually, I didn’t think you gave me any credit at all, as I “could always try an addiction counselor”. So, that’s something.

    You are right that there are definate security issues involved. There’s no denying that. you are openning your machine to the world. And I was answering with my web designer hat and not from the IT perspective. Still the fact of the matter is that a majority of the folks out there use IE for their surfing. 51.6 % of my visitors in March used IE. That number has remained the same for the last year or so. FireFox comes in at 32%. So, if Microsoft doesn’t jump on this, there’s gonna be repercussions. It’s just good that FireFox has no support for animated cursors.

    the only time you hear this type of statement being brought forth is when you have a Windows junkie on the defense

    err… http://www.google.com/search?hl=en&q=Micro%24oft

    there actually are other types of software running in corporate IT.

    No doubt. I associate with many folks that have helped their corporation move away from the MS world. That’s just not the situation where I work and I am in the production world here not on the IT staff.

    you can sync with [...] HotSync

    Actually, I didn’t realize they’d gotten HotSync to work. If that’s possible now, that should be all I need to have. HotSync itself should be able to handle the rest. I will be giving Thunderbird a try. Thanks for that tidbit!

    >Whatever happened to critical thinking in the areas of enterprise security planning?
    It was taken over by the lure of large suites of applications and the promise that “single source solutions” would improve interoperablity and eliminate all incompatiblities between each program. It sounds promissing doesn’t it?

  5. David Keith on April 2nd, 2007 4:18 pm

    Actually, I didn’t think you gave me any credit at all, as I “could always try an addiction counselor”. So, that’s something.

    Man, sure is tough running a blog, isn’t it? Nobody cuts you any slack!

  6. Brian on April 2nd, 2007 4:34 pm

    Ah, the burdens we must bear in this modern world.

    Cheers mate!

Got something to say?





Who is Brian Layman

I am a WordPress expert living in North East Ohio. I am part of the ever expanding Open Source Internet workforce. I am able to stay at home, with my wife and four home schooled kids, while working as the Senior Developer for b5media - a blogging network that has hosted over 300+

I co-host the NEO WordPress Monthly meetup. I am the board chair of our local church. I host and have provided development services for clients such TV personalities Rhett and Link as well as corporations such as Borland International.

In my spare time I try to sneak out, canoe, mountain bike and camp as often as I can. Sometimes I also defend the earth against zombies and aliens, but usually not during the camping trips.

Services Provided

In providing hosting, email, theme and plugin development to my clients, I function as a single point of contact answering to the needs of their expanding sites.

My service portfolio includes but is not limited to WordPress hosting, optimization, theme development and custom plugin creation. Community creation via vBulletin, Ning and BuddyPress and bbpress

I also am well experienced in site conversion, transition and merges. To clarify this, website technologies change and giving up your data is not an option. I have transitioned literally hundreds of sites from one platform to another.

viagra 50 mg indian version of viagra cialis cheapest viagra india online viagra cost comparison viagra for sale without prescription generic tadalafil online buy viagra in korea indian levitra discount cialis online viagra prescription over the counter vardenafil cialis otc cialis no rx cialis 30 mg viagra ranbaxy buy levitra in uk cialis low price tadalafil tablets 10mg cheap viagra fast shipping cheap generic levitra cialis discount cialis 5mg viagra discount prices buy levitra without prescription vardenafil online generic levitra canada viagra professional price cheapest sildenafil citrate indian version of cialis viagra lowest price viagra online prescriptions tadalafil 10mg levitra over the counter levitra prescriptions online buy viagra without a prescription liquid tadalafil citrate buy viagra prescription online tadalafil 20mg india india viagra generic sildenafil citrate for sale vardenafil hcl 10mg cialis discount coupon buy levitra australia viagra over the counter in canada liquid sildenafil tadalafil price comparison viagra cost in india cialis mail order sildenafil sales buy vardenafil cialis offer cheap vardenafil generic cialis no prescription viagra tabs generic indian names viagra price canada vardenafil hcl 20 mg generic viagra without prescription viagra by scilla biotechnologies buy generic cialis free viagra viagra over the counter viagra pills kamagra 100 mg cialis from india tadalafil australia tadalafil 20mg tablets tadalafil soft tabs sildenafil pills viagra no prescription required generic viagra paypal tadalafil online indian viagra cost tadalafil online pharmacy generic soft viagra sildenafil soft tablets viagra generic names buy viagra in ireland levitra without prescription levitra online purchase cialis pill indian tadalafil levitra 5mg cialis cost per pill tadalafil oral jelly sildenafil no prescription vardenafil price generic cialis 10mg cheap cialis no prescription order sildenafil citrate indian generic viagra blue viagra buy cialis usa apcalis 20mg tablets viagra overnight delivery sildenafil india purchase viagra without a prescription viagra prescriptions order viagra without prescription viagra with no prescription levitra for sale purchase viagra canada discount levitra viagra 200mg cheap viagra 100mg cialis overnight delivery buy sildenafil online viagra made in india cialis tabs 10mg viagra indian pharmacy viagra for sale in ireland viagra uk prices buy viagra in europe generic cialis india levitra online viagra for sale india buy viagra in dublin generic cialis soft tabs viagra 50mg cost generic sildenafil 100mg tadalafil generic viagra super active 100 mg kamagra 100mg sildenafil 100 mg tablets cialis no prescription viagra low price online cialis suhagra tablets buy cialis daily use tadalafil sample cialis prices viagra prescription online buy cialis pill kamagra from india cialis online levitra mg vigora india vardenafil 10 mg sildenafil citrate 100mg buy viagra in india buy cialis professional viagra in india buy viagra in singapore generic revatio viagra substitutes sildenafil canada viagra no script cheap kamagra viagra retail price cheap lovegra order viagra uk buy cialis in mexico viagra prescription price purchase cialis online without prescription online cialis prescription ranbaxy caverta buy viagra in hong kong sildenafil price cialis mastercard buy viagra in england viagra mail order canada cialis tablets for sale order cialis cialis soft tabs generic levitra india tadalafil prices cheap sildenafil citrate tablets cialis online prescriptions cialis 5 mg daily levitra prices prescriptions viagra viagra over the counter alternative cialis 20 mg tablets cialis generic india cialis prescribing cialis 20mg daily sildenafil 50 mg viagra drug prices tadalafil generic india cialis sale viagra prices buy viagra 50 mg levitra pharmacy buy viagra generic viagra prescription drug cialis daily cost vardenafil uk viagra soft tabs online buy viagra super active cialis 10mg price 25mg viagra silagra 100mg online viagra prescriptions cialis prescription cheap cialis india revatio 20 mg indian equivalent of viagra tadalafil india viagra capsules cheapest viagra buy cialis without prescription tadalafil overnight cheap tadalafil online purchase viagra online no prescription