Microsoft releases new fix for DLL vulnerability

Posted by   Virus Bulletin on   Sep 1, 2010

Earlier workaround believed to be too complex for most users.

A week after Microsoft released a fix for a DLL vulnerability that affected a large number of programs running on its operating systems, it has released a second fix for the same problem.

DLLs (Dynamic Link Libraries), which contain commonly used functions, are essential to most programs running on Windows operating systems. When a program needs a certain library but doesn't specify its location, Windows looks for libraries in certain places, including the user directory.

By changing this user directory to something it controls and by storing a malicious version of the library there, a piece of malware can make otherwise harmless programs use part of these malicious libraries. Programs that are vulnerable to this kind of attack include Microsoft Office Powerpoint 2007, Skype and Opera.

While software developers are working hard to fix their programs, Microsoft released a workaround last week which prevented insecure DLLs from loading from remote and local file sharing locations. However, the fix meant the user had to make some manual changes to the registry, which can cause harm if not done correctly. Home users in particular were put off by this. The new fix does not have this problem.

More can be found at the blog of security journalist Brian Krebs here, where there is also an explanation of how to apply the fix.

Posted on 01 September 2010 by Virus Bulletin

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

New paper: Collector-stealer: a Russian origin credential and information extractor

In a new paper, F5 researchers Aditya K Sood and Rohit Chaturvedi present a 360 analysis of Collector-stealer, a Russian-origin credential and information extractor.

VB2021 localhost videos available on YouTube

VB has made all VB2021 localhost presentations available on the VB YouTube channel, so you can now watch - and share - any part of the conference freely and without registration.

VB2021 localhost is over, but the content is still available to view!

VB2021 localhost - VB's second virtual conference - took place last week, but you can still watch all the presentations.

VB2021 localhost call for last-minute papers

The call for last-minute papers for VB2021 localhost is now open. Submit before 20 August to have your paper considered for one of the slots reserved for 'hot' research!

New article: Run your malicious VBA macros anywhere!

Kurt Natvig explains how he recompiled malicious VBA macro code to valid harmless Python 3.x code.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.