Microsoft patches Stuxnet and FREAK bugs in Windows

Microsoft has patched an old SSL backdoor of the American government in todays Patch Tuesday. Also a bug that allegedly was abused in an attack on Iranian nuclear centrifuges was fixed. The issue was previously thought to be solved, but should now really be fixed, according to Microsoft.

Windows_logo_-_2012

Initially it was thought that Windows users were not vulnerable to the so-called Freak attack, an old backdoor in SSL allowing attackers to force a lower level of encryption and thus making it possible to eavesdrop on a connection. Later it became known the bug also affected Windows users and now Microsoft has fixed the issue during this Patch Tuesday round.

Also a vulnerability that has been used years ago by the American government in a Stuxnet attack on Iranian nuclear facilities was not properly fixed. The bug was thought to be fixed in 2010, but the issue allowing to execute code on a victim's system was found to still exist. This so-called '.lnk' bug allows an attacker to run code on a system by convincing a victim to open a shortcut to a folder with malicious code.

The German security researcher Michael Heerklotz discovered that the vulnerability could still be abused, Threatpost writes. He was able to find a way to circumvent the measures Microsoft built-in to protect against the issue. It's unclear whether the bug has been abused the last couple of years. One thing is sure, the bug  can be easily abused. An attacker can distribute USB sticks containing the malicious shortcut to victims. As soon as a victim inserts the USB stick the auto-run feature can open a folder which is sufficient to infect a computer.

No posts to display