Live data from Hacker News

Microsoft: 0Day Exploit Targeting Word, Outlook

krebsonsecurity.com

11–20 of 43 posts

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#12

Earlier quoted context omitted.

Serious question -- I don't intend to troll -- I've heard lots of people claim that as soon as OpenOffice et al. get more popular, more malware will target them. It's not as if Microsoft has a monopoly on bugs. Do you think there's ay truth to this line of thinking?

From a security situation, the worst situation is everyone running different mail clients, because then if any one of them has a vulnerability someone can send in a crafted mail to take over their box and gain access to your private company docs. "Monoculture" isn't always bad.

I don't understand this theory that monoculture is safer in a corporate environment. Any interesting organization has more than one secret recipe. Virtually everyone has different access to different systems. If they are all vulnerable to the same bug, the attacker quickly gains control of everything. If they gain control of a single segment, then they can be detected.

The odds of the attack being identified once that segment is compromised is much higher, since everyone else has the opportunity to identify the bad behavior.

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#14

I do wish they would tell us if EMET[1] is an effective mitigation for this vulnerability or not. Considering it involves memory corruption it's likely.. But finding out the hard way would be no fun. [1] http://support.microsoft.com/kb/2458544

"First, our tests showed that EMET default configuration can block the exploits seen in the wild."

http://blogs.technet.com/b/srd/archive/2014/03/24/security-a...

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#15

I'm confused by the idea that there could be a vulnerability while reading RTFs, of all things. Annoying; I frequently send out documents in RTF format to make sure everyone can read them...

I stick with .pdf files

However, that might be bad practice.

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#16
post #3

Earlier quoted context omitted.

Fortunately, I think the current exploits rely on ActiveX controls which are disabled when reading Outlook RTF messages. In fact, I have seen no real world Word exploits using Outlook RTF messages, probably because spear phishing is effective enough.

The advisory says that Office for Mac 2011 is also affected, implying that it's not related to ActiveX controls.

The bug is not related to ActiveX controls, but current exploits for this bug rely on one of them.

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#17

I'm confused by the idea that there could be a vulnerability while reading RTFs, of all things. Annoying; I frequently send out documents in RTF format to make sure everyone can read them...

I stick with .pdf files However, that might be bad practice.

With Adobe Reader it's probably even worse, to be honest.

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#18

Earlier quoted context omitted.

From a security situation, the worst situation is everyone running different mail clients, because then if any one of them has a vulnerability someone can send in a crafted mail to take over their box and gain access to your private company docs. "Monoculture" isn't always bad.

I don't understand this theory that monoculture is safer in a corporate environment. Any interesting organization has more than one secret recipe. Virtually everyone has different access to different systems. If they are all vulnerable to the same bug, the attacker quickly gains control of everything. If they gain control of a single segment, then they can be detected. The odds of the attack being identified once tha…

I think the theory is that once you have any beachhead onto a system, that existing local priv escalation exploits and network mapping techniques are almost always sufficient to complete the exploitation of your corporate network.

So if you have 5 people using 5 different email clients, all 5 of those must be kept secure from spear phishing or email-viewing vulnerabilities to avoid having a hacker get a beachhead on your network.

But if those 5 people are using 1 email client, you only have to keep that 1 safe (and you'd have to keep it safe anyways).

Monocultures are probably bad for drive-by automated hacking though, so I suppose it's a matter of deciding what threat model you're most at risk from.

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#19
post #6

Everyone in my office runs MS Office for inane reasons, I did try to make them move to openoffice/libreoffice w/ thunderbird, we run an open stack behind the scenes and things simply integrate better.. I feel like this is a massive 'told ya so' after spending thousands of pounds of company money on licenses, now I'll have to spend hours of my time fixing everyones machine one by one, just in case. >_ hopefully a fix…

Serious question -- I don't intend to troll -- I've heard lots of people claim that as soon as OpenOffice et al. get more popular, more malware will target them. It's not as if Microsoft has a monopoly on bugs. Do you think there's ay truth to this line of thinking?

I don't think they'll ever get that popular. Malware still isn't targeting Word and Outlook for Mac, despite them being vulnerable, so OpenOffice has a long way to go.

Re: Microsoft: 0Day Exploit Targeting Word, Outlook

#20

I do wish they would tell us if EMET[1] is an effective mitigation for this vulnerability or not. Considering it involves memory corruption it's likely.. But finding out the hard way would be no fun. [1] http://support.microsoft.com/kb/2458544

It's usually the case that EMET blocks the "standard" exploit, but it can be bypassed with a little more work. It depends on the bug, but there are real world cases for which many have exploits that fully bypass EMET with all settings on.
Post reply on HN