AplusWebMaster
Topic Starter
FYI…
- http://support.microsoft.com/kb/971778#FixItForMeAlways
(Get the Enable Workaround "FixIt" here. MUST be run in Admin mode.)
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1537
CVSS v2 Base Score:9.3 (HIGH)
- http://preview.tinyurl.com/luqvka
06-17-2009 Symantec Security Response Blog - "… Some of the first pages to use this exploit for this vulnerability in the wild were linked from phishing pages. The phishing pages in question not only attempted to steal the visitors’ login credentials, but also silently redirected users to a malicious Web page hosting an exploit for the DirectShow vulnerability (CVE-2009-1537). This malicious Web page loads a corrupt .avi file that exploits the vulnerability and also loads some additional malicious .dlls to facilitate reliable exploitation of the user’s machine… The malicious .dlls in turn download an encoded .exe payload that, in this case, ultimately leads to Trojan.Cipevas being loaded on to the victim’s machine. Trojan.Cipevas then connects back to the attackers’ website (the same one where the exploit page is hosted), sends some minimal user information to the attacker and then waits for further commands from the attacker… The phishing page observed in this case was for a well-known webmail login page… The attackers were hosting the fake login page on their own servers, so the URL displayed in the location bar was obviously not the real URL you would expect to see… although the main purpose of this fake login page is to steal user credentials, the page also contains an iframe that redirects to the DirectShow exploit page. As usual in these types of attacks, the width and height of the iframe are set to zero to hide it from the user… it is not a typical buffer overflow/heap corruption vulnerability; rather, the vulnerability only allows one byte in memory to be overwritten. This means that the creator of the exploit code had to think outside the box to get this vulnerability to be exploitable…"
(Screenshots available at the Symantec URL above.)

- http://support.microsoft.com/kb/971778#FixItForMeAlways
(Get the Enable Workaround "FixIt" here. MUST be run in Admin mode.)
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-1537
CVSS v2 Base Score:9.3 (HIGH)
- http://preview.tinyurl.com/luqvka
06-17-2009 Symantec Security Response Blog - "… Some of the first pages to use this exploit for this vulnerability in the wild were linked from phishing pages. The phishing pages in question not only attempted to steal the visitors’ login credentials, but also silently redirected users to a malicious Web page hosting an exploit for the DirectShow vulnerability (CVE-2009-1537). This malicious Web page loads a corrupt .avi file that exploits the vulnerability and also loads some additional malicious .dlls to facilitate reliable exploitation of the user’s machine… The malicious .dlls in turn download an encoded .exe payload that, in this case, ultimately leads to Trojan.Cipevas being loaded on to the victim’s machine. Trojan.Cipevas then connects back to the attackers’ website (the same one where the exploit page is hosted), sends some minimal user information to the attacker and then waits for further commands from the attacker… The phishing page observed in this case was for a well-known webmail login page… The attackers were hosting the fake login page on their own servers, so the URL displayed in the location bar was obviously not the real URL you would expect to see… although the main purpose of this fake login page is to steal user credentials, the page also contains an iframe that redirects to the DirectShow exploit page. As usual in these types of attacks, the width and height of the iframe are set to zero to hide it from the user… it is not a typical buffer overflow/heap corruption vulnerability; rather, the vulnerability only allows one byte in memory to be overwritten. This means that the creator of the exploit code had to think outside the box to get this vulnerability to be exploitable…"
(Screenshots available at the Symantec URL above.)