{"id":15227,"date":"2010-09-16T11:28:00","date_gmt":"2010-09-16T09:28:00","guid":{"rendered":""},"modified":"2010-09-16T11:28:00","modified_gmt":"2010-09-16T09:28:00","slug":"microsoft-and-kaspersky-co-operate-to-patch-windows","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/software\/15227-microsoft-and-kaspersky-co-operate-to-patch-windows.html","title":{"rendered":"Microsoft and Kaspersky co-operate to patch Windows"},"content":{"rendered":"<p>Kaspersky Lab announced that it has co-operated with Microsoft in successfully closing a serious vulnerability in Microsoft Windows.<\/p>\n<p>The vulnerability was classified as being of the &lsquo;zero-day&rsquo; type when it was detected, and has been used by the notorious Stuxnet worm. Worm.Win32.Stuxnet is remarkable in that it is basically an industrial espionage tool &#8211; it is designed to gain access to the Siemens WinCC operating system which is responsible for data collection and monitoring production.<\/p>\n<p>Ever since it first emerged in July 2010, IT security specialists have watched Worm.Win32.Stuxnet closely. Kaspersky Lab says that it has gone to great lengths to research Stuxnet&rsquo;s capabilities and has discovered that, in addition to the vulnerability when processing LNK and PIF files that was detected originally, it also uses four other vulnerabilities in Windows.<\/p>\n<p>One such example is MS08-067, which was also used by the infamous Kido (Conficker) worm in early 2009. The other three vulnerabilities were previously unknown and exist in the current versions of Windows.<\/p>\n<p>Along with MS08-067, Stuxnet also uses another vulnerability to propagate.<\/p>\n<p>This vulnerability exists in the Windows Print Spooler service and can be used to send malicious code to a remote computer where it is then executed.<\/p>\n<p>By virtue of the features of this vulnerability, the infection can spread to computers using a printer or through shared access to one. Having infected a computer connected to a network, Stuxnet then attempts to spread to other computers.<\/p>\n<p>Kaspersky says that they immediately reported the vulnerability to Microsoft when they detected it.<\/p>\n<p>Microsoft then analysed it themselves and agreed with Kaspersky Lab&rsquo;s findings. The vulnerability was classified as a Print Spooler Service Impersonation Vulnerability and was rated as &lsquo;critical&rsquo;. Microsoft immediately started working to close the loophole and subsequently released the MS10-061 patch on 14 September 2010.<\/p>\n<p>Kaspersky says that they detected yet another zero-day vulnerability in the Stuxnet code. It was classified as an &lsquo;Elevation of Privilege&rsquo; (EoP) vulnerability which could be exploited by the worm to gain full control over the infected computer.<\/p>\n<p>A similar EoP-class vulnerability was detected by Microsoft&rsquo;s experts, Kaspersky says. Both will be corrected in future security updates for Windows operating systems.<\/p>\n<p>Kaspersky honoured Alexander Gostev, Chief Security Expert at Kaspersky Lab, who they say played an active role in identifying the new threat and co-operated closely with Microsoft to resolve the issue.<\/p>\n<p>&ldquo;Stuxnet was the first malware program to simultaneously exploit as many as four vulnerabilities,&rdquo; said Alexander Gostev. &ldquo;This makes Stuxnet truly unique: it is the first threat we have encountered that contains this many surprises in a single package. Before we detected this new vulnerability, it would have been worth a fortune to hackers. Given Stuxnet also uses Realtek and Jmicron digital certificates &ndash; and remember too that it was ultimately designed to steal the data stored in Simatic WinCC SCADA &ndash; all of this makes this threat truly unprecedented. It has to be said, the malware writers have demonstrated quite remarkable programming skills.&rdquo;<\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/268039-Kaspersky-and-Microsoft-tackle-Windows-vulnerability-together\" target=\"_self\" title=\"Microsoft and Kaspersky co-operate to patch Windows\">Microsoft and Kaspersky co-operate to patch Windows<\/a> <\/strong>&lt;&lt; Comments and views<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky Lab announces its collaboration with Microsoft to close a zero-day vulnerability used to by the Stuxnet malware family to exploit Windows<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[],"class_list":["post-15227","post","type-post","status-publish","format-standard","hentry","category-software"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/15227"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=15227"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/15227\/revisions"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=15227"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=15227"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=15227"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}