AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?storyid=1837
Last Updated: 2006-11-08 18:53:37 UTC
"Rohit from Tippingpoint advised us that he is seeing a large number of attacks from Russia using an un-patched vulnerability in the WMIObjectBroker ActiveX control (CVE-2006-4704*). He is seeing it used as part of a drive-by download. Typically, the Trojan "Galopoper.A"** is loaded. There is no patch available at this point… The WMIObjectBroker ActiveX component is part of Visual Studio 2005 and associated with the WmiScriptUtils.dll . So you are only vulnerable if you find WmiScriptUtil.dll on your system. Also, by default this ActiveX component is not activated by default. For more details about this vulnerability see http://www.microsoft.com/technet/security/…ory/927709.mspx ."
"• November 08, 2006: Advisory updated to alert customers that we are aware of attacks using the reported vulnerability."
* http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4704
** http://www.symantec.com/security_response/…-042013-1813-99
"…Trojan.Galapoper.A is a Trojan horse contacts a remote Web site and downloads other risks onto the compromised computer…"
- http://isc.sans.org/diary.php?storyid=1813
- http://secunia.com/advisories/22603
- http://www.kb.cert.org/vuls/id/854856

- http://isc.sans.org/diary.php?storyid=1837
Last Updated: 2006-11-08 18:53:37 UTC
"Rohit from Tippingpoint advised us that he is seeing a large number of attacks from Russia using an un-patched vulnerability in the WMIObjectBroker ActiveX control (CVE-2006-4704*). He is seeing it used as part of a drive-by download. Typically, the Trojan "Galopoper.A"** is loaded. There is no patch available at this point… The WMIObjectBroker ActiveX component is part of Visual Studio 2005 and associated with the WmiScriptUtils.dll . So you are only vulnerable if you find WmiScriptUtil.dll on your system. Also, by default this ActiveX component is not activated by default. For more details about this vulnerability see http://www.microsoft.com/technet/security/…ory/927709.mspx ."
"• November 08, 2006: Advisory updated to alert customers that we are aware of attacks using the reported vulnerability."
* http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4704
** http://www.symantec.com/security_response/…-042013-1813-99
"…Trojan.Galapoper.A is a Trojan horse contacts a remote Web site and downloads other risks onto the compromised computer…"
- http://isc.sans.org/diary.php?storyid=1813
- http://secunia.com/advisories/22603
- http://www.kb.cert.org/vuls/id/854856