This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

WMIObjectBroker ActiveX 0-Day exploit in the wild

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1837
Last Updated: 2006-11-08 18:53:37 UTC
"Rohit from Tippingpoint advised us that he is seeing a large number of attacks from Russia using an un-patched vulnerability in the WMIObjectBroker ActiveX control (CVE-2006-4704*). He is seeing it used as part of a drive-by download. Typically, the Trojan "Galopoper.A"** is loaded. There is no patch available at this point… The WMIObjectBroker ActiveX component is part of Visual Studio 2005 and associated with the WmiScriptUtils.dll . So you are only vulnerable if you find WmiScriptUtil.dll on your system. Also, by default this ActiveX component is not activated by default. For more details about this vulnerability see http://www.microsoft.com/technet/security/…ory/927709.mspx ."
"• November 08, 2006: Advisory updated to alert customers that we are aware of attacks using the reported vulnerability."

* http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4704

** http://www.symantec.com/security_response/…-042013-1813-99
"…Trojan.Galapoper.A is a Trojan horse contacts a remote Web site and downloads other risks onto the compromised computer…"

- http://isc.sans.org/diary.php?storyid=1813

- http://secunia.com/advisories/22603

- http://www.kb.cert.org/vuls/id/854856

:ph34r:
FYI…

- http://www.darkreading.com/document.asp?do…&print=true
NOVEMBER 9, 2006
"Attackers are launching new assaults on Windows, using an unpatched, critical zero-day bug in Visual Studio 2005. The exploits employ an unusual method of downloading known trojans onto their fake Websites.(See Hackers Aim at Microsoft Visual Studio 2005.) "We started seeing several hundreds of hits from various IP addresses this weekend," says Mike Dausin, a security researcher at TippingPoint. The attacks are originating from Russia, he says. "They are using this vulnerability to install viruses on computers in the U.S." Microsoft has acknowledged that there are exploits in the wild of this vulnerability, but there confusion remains over whether or not this is actually the first time it was exploited in a real attack. TippingPoint's Dausin says this is the first known attack using the bug that his company is aware of. The bug was first revealed publicly by Microsoft on October 31, and TippingPoint says it first reported it to Microsoft in June. But researcher HD Moore says he heard about the attack in July from a hacker who was already exploiting the as-yet unpublicized bug to install adware, and that he informed Microsoft about it. It's unclear if the bug will be included among the security bulletins in Microsoft's Patch Tuesday Nov. 14…"

:ph34r: