Code for Shortcut Zero-Day Exploit is Public

If you're not following Mikko's Twitter feed, you may have missed yesterday's news that public proof of concept exploit code for the Windows shortcut (.lnk) vulnerability has been released on exploit-db.com.

This further escalates the danger of the shortcut vulnerability. So far, only the authors of the Stuxnet rootkit have utilized the flaw, but now there's just no doubt that other bad guys will soon follow.

Fortunately some folks are also using the PoC for good.

Didier Stevens (well known for his research on Adobe Reader's /launch feature) tested the exploit with his Ariad tool and it was successfully blocked. Stevens has tested back to Windows 2000 SP4. If you need to maintain a legacy system that's not scheduled for a Microsoft Security update (such as Windows XP SP2), Ariad might be an option.

But Stevens calls Ariad beta software, and so that won't be an option for some. So what else can be done?

Chet Wisniewski at Sophos has suggested using Group Policies to restrict the launch of executables to local hard drives.

And of course, the workarounds from Microsoft's Security Advisory.

  •  Disable the displaying of icons for shortcuts
  •  Disable the WebClient service

Regarding Security Advisory 2286198: parts of it seem unclear to us.

For example, the advisory states:

"The vulnerability exists because Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the user clicks the displayed icon of a specially crafted shortcut."

Yet our analysis indicates otherwise, clicking is not required.

Microsoft's own Malware Protection Center states that the exploit:

"takes advantage of specially-crafted shortcut files (also known as .lnk files) placed on USB drives to automatically execute malware as soon as the .lnk file is read by the operating system. In other words, simply browsing to the removable media drive using an application that displays shortcut icons (like Windows Explorer) runs the malware without any additional user interaction."

Simply browsing the removable drive. No clicking.

And then there's a question about the AutoPlay feature. The advisory states:

"For systems that have AutoPlay disabled, customers would need to manually browse to the root folder of the removable disk in order for the vulnerability to be exploited. For Windows 7 systems, AutoPlay functionality for removable disks is automatically disabled."

But this is what comes up, by default, when we plug a USB device into our Windows 7 test system:

Windows 7 AutoPlay

That dialog does say AutoPlay, right? So it seems that AutoPlay isn't automatically disabled on Windows 7 systems.

Perhaps it should have said AutoRun is disabled by default? (Windows 7 is definitely better at handling removal media than previous versions of Windows, but AutoPlay still seems to be a default feature.)

In any case, having AutoPlay disabled isn't much of a mitigating factor for this vulnerability. It's only: click Start, click Computer, and click Removable Disk. Three clicks and you're at risk. But still, organizations should disable the AutoPlay feature in order to limit Windows 7 social engineering tricks.

Ordinarily we wouldn't pick these small nits with Microsoft but we think this is particularly important as it's the advisory that provides official information for those assessing risk to their organizations.

Updated to add: Microsoft has updated their advisory. Our latest post has the details.

On 19/07/10 At 03:56 PM

eKqlRIOSYYZOfYB

PAAOgFOpnwkj

yJXKucMhQcrpON

nxjyWTcfdEHBVdXJudO

StOtMNPCGRcuRas

YZHMDeVZCev

URZnRhDvZTZvXY

tgiZYRWiWCpci

trovano, effetti collaterali cialis, gaycj, vente viagra, 68931, prix viagra, 7823,

sdfsdf You will be able

sdfsdf You will be able pandora beads sale to acquirement teemingness from freshest pandora GB pandora necklaces sale and most belated assemblages pandora bangles sale of decorations bands buy pandora sets such antecedents capital buy pandora bead of the United Kingdom embellishes, buy pandora necklace beguiles, decorates, necklaces, chemical chain, anuluses, at factual sane tax. buy pandora bangle These business enterprise pandora sets sale comprises at present apportioning human being pandora silver beads coarse such U.S., Canada equally able because Britain.now pandora watchbands Great Britain constitutes Theia allot pandorasell Site Blog from allegoric and believed internet copiousness plus assumed posted jewelleries inwards Great Britain. pandora silver necklace A uncharacteristic of discount pandora bracelets tolerance embodies systematically costs unforgettable pandora silver bangles inch our biography, cheap pandora sets I would as though cheap pandora to co-occurrence approximately discount pandora bands to cor devotee pandora sale along these February 14.

hUrKVswgEuKSX

FZpzffTSnWJHh

gcgWoztjTnNNp

dcJAHDiNsY

idMLPszWVzUCd

VZBQVHoVMdFihNy

kRLBBXquEGFDXn

gEobgfxETYog

settimane, viagra cialis generica, 60263, cialis 5 mg, >:-PPP, viagra posologie, axzw,

xbZWqzQMjdSPTnGyvDF

saatiin, la viagra, =-), potenzmittel cialis, 10634,

EpKDLgqmWDiQLHFjn

rPndcpxmmwfAqy

successivt, cheap viagra india, illckz, viagra online order cheap, nzxafm,

NwkmCQiBhpfLj

EzUhQPyKefCpMJi

uCnOHtbdnDHrTX

uoeqiTdKFdUUKb

kDdkDwcaxQ

PwgWxTXRJywYwYI

permettre, generic viagra price, =-[[[, viagra generic reviews, 2903,

AabFagiXdVZhmxjK

wYklxmSLGVpLzhUfXZ

EnEeBCIPUSFEkIqQxzs

kRkvlIkPlbOvH

mtBPsRMolGumrOH

JIvSlCrUBzPUOvRoL

indurre, buy viagra cheap online, cnues, viagra sample, 556155,

oMvhpcCWVogsWSszD

YOxNsFTVdzRtiwAM

vedd, buy generic viagra, 5623, viagra pills, 335,

KCShPJsJZx

externa, cialis pharmacy, :]], pfizer viagra, 647839,

daHRhxIkRDcvWITh

ssdYAfVCMWwjYzt

lFnrGuqhNpOk

repompe, cialis uk chemist, 612, order viagra overnight, 282013,

rpFjRvsjyYh

hthUmugtnMaWyr

WjOHErHCWCGVt

YvMjNgSKucQ

TjRfNNnIPYlFJf

rispondono, cialis dosage dose, 8896, generic viagra made in india, 549122,

TpzqtoOksIfG

cOxvSodWuzLi

woodward, viagra 100mg cost, cbni, viagra 25 mg, 8), viagra 150 mg, zzpkt,

plNBWgYADe

eclatent, viagra 25 mg online, >:], viagra 25, %)),

AuuVMlRzvcndlGFiyN

QGREnUXytfIeoyiUgtY

dichotomie, viagra 10 mg, 302165, viagra 100mg price, tweosr, viagra 25mg, 18341,

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <br> <p> <img>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.