10 new vulnerabilities found in XP SP2
Posted: Sun Nov 14, 2004 4:25 am
Finjan Software, a provider of secure content management solutions for enterprises, have found no less than ten serious security vulnerabilities in the Microsoft Windows XP Service Pack 2 (SP2) operating system.
The security firm, based in California, has provided Microsoft with full technical details concerning the vulnerabilities discovered by Finjan's Malicious Code Research Center and has been assisting Microsoft to patch these holes. In order to prevent the creation of malicious viruses and worms, Finjan will not be releasing any technical details about these vulnerabilities until they are fully patched by Microsoft.
Shlomo Touboul, CEO and Founder of Finjan Software said,
"The recently released Service Pack 2 of Microsoft® Windows® XP operating system offers certain features of security. However, it suffers because it is still basically the same operating system and has some major flaws which compromise end-user security. By using Finjan's proactive security solutions, based on our patented behaviour blocking technology on top of SP2, users can enjoy a secure environment that protects them from such vulnerabilities."
By exploiting all vulnerabilities discovered in SP2 by Finjan, attackers can silently and remotely take over a machine when the user simply browses a web page.
The following scenarios provided by Finjan detail some of the vulnerabilities discovered in SP2:
• Hackers can remotely access users' local files
Windows XP SP2 is designed to deny access to a local file in the course of Internet browsing. Therefore, any attempt by a remote web page to access a local file in any way other than downloading a file, is denied. Finjan has shown that this feature can be remotely compromised by hackers.
• Hackers can switch between Internet Explorer Security Zones to obtain rights of local zone.
Internet Explorer uses the notion of security zones to differentiate between mobile codes by their origin. In this way, for example, the permissions of files running from the local hard drive are much higher than the permissions of code downloaded from the Internet. Finjan has shown that it is possible to elevate the privilege level of mobile code downloaded from the Internet. By gaining additional privileges, the remote code could read, write and execute files on the user's hard drive.
• Hackers can bypass SP2's notification mechanism on the download and execution of EXE files and therefore download files without any warning or notification.
One of the mechanisms that have been implemented in SP2 is the verification of the download and the execution of content arriving from the Internet. This mechanism is implemented by three new features - an information bar inside Internet Explorer which filters and blocks unauthorized operations performed by web pages, a file download dialog which requires the user's confirmation for file save and execution operations, and an execution verification dialog. These features are important to prevent unauthorized silent 'drive-by' installations of malicious software.
[url=\"http://itvibe.com/default.aspx?NewsID=3012\"][Source][/url]
The security firm, based in California, has provided Microsoft with full technical details concerning the vulnerabilities discovered by Finjan's Malicious Code Research Center and has been assisting Microsoft to patch these holes. In order to prevent the creation of malicious viruses and worms, Finjan will not be releasing any technical details about these vulnerabilities until they are fully patched by Microsoft.
Shlomo Touboul, CEO and Founder of Finjan Software said,
"The recently released Service Pack 2 of Microsoft® Windows® XP operating system offers certain features of security. However, it suffers because it is still basically the same operating system and has some major flaws which compromise end-user security. By using Finjan's proactive security solutions, based on our patented behaviour blocking technology on top of SP2, users can enjoy a secure environment that protects them from such vulnerabilities."
By exploiting all vulnerabilities discovered in SP2 by Finjan, attackers can silently and remotely take over a machine when the user simply browses a web page.
The following scenarios provided by Finjan detail some of the vulnerabilities discovered in SP2:
• Hackers can remotely access users' local files
Windows XP SP2 is designed to deny access to a local file in the course of Internet browsing. Therefore, any attempt by a remote web page to access a local file in any way other than downloading a file, is denied. Finjan has shown that this feature can be remotely compromised by hackers.
• Hackers can switch between Internet Explorer Security Zones to obtain rights of local zone.
Internet Explorer uses the notion of security zones to differentiate between mobile codes by their origin. In this way, for example, the permissions of files running from the local hard drive are much higher than the permissions of code downloaded from the Internet. Finjan has shown that it is possible to elevate the privilege level of mobile code downloaded from the Internet. By gaining additional privileges, the remote code could read, write and execute files on the user's hard drive.
• Hackers can bypass SP2's notification mechanism on the download and execution of EXE files and therefore download files without any warning or notification.
One of the mechanisms that have been implemented in SP2 is the verification of the download and the execution of content arriving from the Internet. This mechanism is implemented by three new features - an information bar inside Internet Explorer which filters and blocks unauthorized operations performed by web pages, a file download dialog which requires the user's confirmation for file save and execution operations, and an execution verification dialog. These features are important to prevent unauthorized silent 'drive-by' installations of malicious software.
[url=\"http://itvibe.com/default.aspx?NewsID=3012\"][Source][/url]