This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

MS Access exploit...

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.avertlabs.com/research/blog/ind…ts-nothing-new/
March 6, 2008 - "Recently our friends from Pandalabs published a weblog*, stating there is a new Microsoft access exploit found in the wild. We initiated some research on this exploit and found it actually targets an older well known vulnerability, CVE-2005-0944**, found by the hexview team in March 2005. It’s very easy to exploit this vulnerability. We had observed similar exploits last year, and the dropper used in this case looks very similar to that one. Microsoft considers MDB files to be unsafe, so a specific patch for this vulnerability has not been released since it was made public 3 years ago… Since Microsoft doesn’t patch Access-related vulnerabilities, we highly recommend Office users -never- open untrusted MDB files."

* http://pandalabs.pandasecurity.com/archive…ss-exploit.aspx
3 March 08

** http://nvd.nist.gov/nvd.cfm?cvename=CVE-2005-0944
FYI…

- http://preview.tinyurl.com/2reg7d
March 20, 2008 (Symantec Security Response Weblog) - "…Our friends at Panda blogged about a possible (new?) vulnerability of the MS Jet library on March 3rd and McAfee also blogged this past December about a different vulnerability reported on Bugtraq. Here at Symantec we also reported some of these vulnerabilities to Microsoft and also the many targeted attacks carried with .mdb files since March 2006, but this is almost the usual sort of response:
"You appear to be reporting an issue with a file type Microsoft considers to be unsafe. Many programs, such as Internet Explorer and Outlook, automatically block these files. For more information, please visit http://support.microsoft.com/kb/925330 "
This sentence translates into a very simple equation: .mdb = .exe. Microsoft does not acknowledge the bug as a critical remote execution vulnerability because .mdb files are considered unsafe and so Outlook is configured to block Access files when received as attachment. However, I doubt that all users aware of that… it’s the combination of .doc and .mdb that makes the attack effective. However, enticing victims to save and open these files from the same folder is not such an unrealistic scenario (putting both files in the same .zip archive before sending the mail may be enough)… The two files are detected as Trojan.Mdropper (.doc) and Trojan.Acdropper (.mdb), while the dropped executable is detected as Backdoor.Trojan. The files are sent with the filename “Nokia_7650_video_en.doc” and “v_080310.asd.” At the moment, the most frequent exploits for MSJET40.DLL (-are-) used in the wild…"

:ph34r: