Microsoft releases manual fix for Duqu zero-day
- 05 November, 2011 06:42
- Comments
Microsoft has released a Fix-it tool to allow Windows users to manually patch their systems to thwart the Duqu Trojan: Microsoft Security Advisory (2639658).
Duqu, or "son of Stuxnet" as some call it, is worrisome because it installs a keystroke logger and then can replicate itself, even across secure networks, using the passwords obtained. It communicates with other servers across the Internet, giving hackers access. The malware will remove itself after 30 days.
In its Security Advisory, Microsoft confirmed that it is seeing attacks in the wild, but downplayed the impact. The Advisory said, "Microsoft is investigating a vulnerability in a Microsoft Windows component, the Win32k TrueType font parsing engine. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. We are aware of targeted attacks that try to use the reported vulnerability; overall, we see low customer impact at this time. This vulnerability is related to the Duqu malware."
Nevertheless, Microsoft did release a "Fix-it" tool that allows IT professionals to manually disable the code with the hole in their systems. It does have some drawbacks in that, "Applications that rely on embedded font technology will fail to display properly," Microsoft warns. Additionally, IT professionals can also manually perform the fix by entering in a series of commands at an administrative prompt. The Fix-It is for all versions of Windows. Here is a link to it. The manual commands are available via Microsoft's Security Advisory, under "Workarounds."
Microsoft is still investigating if it will also release a patch. If so, this patch is not currently scheduled to be part of Tuesday's batch.
Julie Bort is the editor of Network World's Microsoft Subnet and Open Source Subnet communities. She writes the Microsoft Update and Source Seeker blogs. Follow Bort on Twitter @Julie188.
Read more about wide area network in Network World's Wide Area Network section.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Microsoft Subnet: An independent Microsoft community
- Windows Research Center - Network World
- Microsoft Security Advisory (2639658): Vulnerability in TrueType Font Parsing Could Allow Elevation of Privilege
- Applications Research Center - Network World
- Here is a link to it
- LAN & WAN Research Center - Network World
-
FTC chairman: Do-not-track law may not be needed
-
Kindle sales soar but Amazon mum on actual numbers
-
Wall Street Beat: IPOs, M&A, chip news stir tech optimism
-
Anonymous Takes Aim at Indian Government
-
Java creator: Fears over consequences of possible Oracle trial win may be overblown
-
Microsoft Office
-
Office 2007 All-In-One Desk Reference for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 for Dummies
-
Windows 7 for Dummies®
-
Windows 7 for Dummies® Dvd+book Bundle
-
Teach Yourself Visually Windows 7
-
MYOB Software for Dummies 6E Australian Edition
-
Excel 2007 All-In-One Desk Reference for Dummies









Comments
Post new comment