The_Unbeliever
Honorary Master
And another 0-day vulnerability is found...
Link to The Register.
Threat intelligence firm iSight partners has announced the discovery of a zero-day - apparently used in Russian attacks on NATO and the EU - that impacts desktop and server versions of Windows, from Vista and Server 2008 to current versions.
The firm has dubbed vulnerability CVE-2014-4114 “SandWorm” and this one looks to be as terrible as Shai-Hulud in full cry, as iSight says it was “used in [a] Russian cyber-espionage campaign targeting NATO, European Union, Telecommunications and Energy sectors.”
The zero-day is “An exposed dangerous method vulnerability exists in the OLE package manager in Microsoft Windows and Server” that “allows an attacker to remotely execute arbitrary code.”
Link to The Register.