Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Patch! Microsoft emits emergency fix for THIRD Hacking Team hole (Critical Windows Vulnerability)
The Register ^ | July 20, 2015 | Chris Williams

Posted on 07/20/2015 1:58:13 PM PDT by dayglored

Microsoft has, in the past couple of minutes, released a security update for all supported versions of Windows to fix a critical remote-code execution vulnerability.

Details of the vulnerability were found and reported to Microsoft by security researchers poring over internal memos leaked online from spyware-maker Hacking Team. This follows an elevation-of-privilege hole in Windows, and a remote-code execution vuln in Internet Explorer 11, that were also uncovered from the Hacking Team files, and patched last week by Microsoft.

This latest security flaw (MS15-078) lies within the Windows Adobe Type Manager Library, and can be exploited by attackers to hijack PCs, infect them with malware, and so on. A victim who opens a document or even a webpage that contains a malicious embedded OpenType font file can be attacked thanks to this vulnerability.

Microsoft explained in an advisory:

An attacker who successfully exploited this vulnerability could take complete control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

There are multiple ways an attacker could exploit this vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage that contains embedded OpenType fonts. The update addresses the vulnerability by correcting how the Windows Adobe Type Manager Library handles OpenType fonts.

When this security bulletin was issued, Microsoft had information to indicate that this vulnerability was public but did not have any information to indicate this vulnerability had been used to attack customers. Our analysis has shown that exploit code could be created in such a way that an attacker could consistently exploit this vulnerability.

...

(Excerpt) Read more at theregister.co.uk ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: malware; vulnerability; windows; windowspinglist
Do Not Delay -- Patch (RUN WINDOWS UPDATES) Now!
1 posted on 07/20/2015 1:58:13 PM PDT by dayglored
[ Post Reply | Private Reply | View Replies]

To: dayglored; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
Run Windows Update NOW -- this is serious! ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to ShadowAce for the heads up!!

2 posted on 07/20/2015 1:59:44 PM PDT by dayglored (Meditate for twenty minutes every day, unless you are too busy, in which case meditate for an hour.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Except for one thing: I don’t run Internet Explorer as my default web browser. I run Google Chrome Version 43.0.2357.134 as my default web browser.


3 posted on 07/20/2015 2:12:27 PM PDT by RayChuang88 (FairTax: America's economic cure)
[ Post Reply | Private Reply | To 1 | View Replies]

To: RayChuang88
Sorry, NO. Chrome doesn't save you. Read again -- the mention of IE had to do with a PREVIOUS flaw already patched.

This one is in a Windows OS font driver common to all version. Doesn't have anything to do with which browser you use.

https://technet.microsoft.com/library/security/MS15-078

4 posted on 07/20/2015 2:30:45 PM PDT by dayglored (Meditate for twenty minutes every day, unless you are too busy, in which case meditate for an hour.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: RayChuang88

None of my biz - intention is to ensure people know that Google Chrome (and actually All Google products share your data with it’s servers, unless you take specific action to disable their privacy breaching data exfiltrating features.
Google is a Bad anti-right to privacy actor.
Here’s a paper Google authors explaining how they get your data and all of the measures you need to take to disable that.
https://www.google.com/chrome/browser/privacy/whitepaper.html

I use Firefox Mozilla in Privacy mode, and only conduct searches using Startpage.com <- they are hosted in the Netherlands and do not keep your search info.
(However you ISP may).


5 posted on 07/20/2015 2:45:28 PM PDT by MarchonDC09122009 (When is our next march on DC? When have we had enough?)
[ Post Reply | Private Reply | To 3 | View Replies]

To: MarchonDC09122009
I don't like Firefox because each tab on the browser does NOT run as its own process (unlike Internet Explorer 11.0 and Chrome). As such, one misbehaving tab can literally cause a full browser crash, something I really dislike. If the Mozilla people fixes that, then I may consider going to Firefox full-time.
6 posted on 07/20/2015 2:52:41 PM PDT by RayChuang88 (FairTax: America's economic cure)
[ Post Reply | Private Reply | To 5 | View Replies]

To: dayglored

Done, thanks.


7 posted on 07/20/2015 2:52:56 PM PDT by Excellence (Marine mom since April 11, 2014)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Thank you


8 posted on 07/20/2015 2:56:00 PM PDT by novemberslady
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

Thanks for the heads-up, guys!


9 posted on 07/20/2015 3:15:06 PM PDT by W. (I've said there's no original thought left in Hollywood for A. Long. Time.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

Wow, that’s NASTY. Kernel-mode access from a simple website font. YIKES!


10 posted on 07/20/2015 3:21:48 PM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: rarestia

Wanna bet it is Yet Another Buffer Overflow... the problem is not the font — it is the silly software that is supposed to be able to handle it correctly no matter what it is.

To assume that third party data is always going to be friendly to your application is very foolish!


11 posted on 07/20/2015 3:34:52 PM PDT by HiTech RedNeck (Embrace the Lion of Judah and He will roar for you and teach you to roar too. See my page.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: HiTech RedNeck

This is a kernel-mode vulnerability that takes advantage of the fact that Microsoft’s font controls are at the kernel. Fonts are often cited as a vector for vulnerabilities due to the need for elevated privileges to display them. Not sure I understand the mechanism well enough, but I don’t think it’s buffer overflow. I’ve been wrong before.

It’s also worthwhile to note this is related to OpenType fonts, which are very popular in web design, as I understand it.


12 posted on 07/20/2015 3:41:27 PM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: rarestia

Something is causing the driver to go looey... you’d think that part of the kernel would be armor plated against this kind of roto rooter. Data that goes one inch beyond what it should will be cut off. Still thinking buffer overflow, that is Occam’s Razor view of the problem.


13 posted on 07/20/2015 3:43:55 PM PDT by HiTech RedNeck (Embrace the Lion of Judah and He will roar for you and teach you to roar too. See my page.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: HiTech RedNeck

I’ve seen attacks occur without so much as a blip in resource monitoring. The most reliable monitoring for hacking is through network tools. It’s amazing what the Chinese and Russians try to do against your average network on a daily basis.


14 posted on 07/20/2015 3:49:15 PM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: rarestia

I’s talking about sofwere injuneerin. The wildcat wants to get loose, so you put ‘im in a cage. Simple no? HiTech


15 posted on 07/20/2015 4:00:55 PM PDT by HiTech RedNeck (Embrace the Lion of Judah and He will roar for you and teach you to roar too. See my page.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: HiTech RedNeck

You’re 100% by my estimation. I’m a systems architect, but I can’t argue with your logic.


16 posted on 07/20/2015 4:02:32 PM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: dayglored

Bump! Thanks for the heads up!


17 posted on 07/21/2015 9:53:22 AM PDT by Perseverando (For Progressives, Islamonazis & Totalitarians: It's all about PEOPLE CONTROL!)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson