The Enterprise Security Supersite
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Network Security Viruses & Malware Spam & Hackers Security Products More Topics...
Windows Security
Average Rating:
Rate this article:  
First Windows 7 Exploit Appears To Evade SDL Process First Windows 7 Exploit Appears To Evade SDL Process
By Jennifer LeClaire
November 13, 2009 10:23AM

Bookmark and Share
The first zero-day exploit in Windows 7 has been reported by security researcher Laurent Gaffié, who questioned if Microsoft's Secure Development Lifecycle process exists. The Windows 7 exploit appears to take advantage of a bug in the Server Message Block protocol for file sharing. Windows 7 was not patched on Patch Tuesday.
 


Windows Relevant Products/Services 7 escaped the monthly patching process earlier this week, but it didn't escape the notice of hackers. What some security researchers are calling the first zero-day exploit in Windows 7 has been identified and Microsoft Relevant Products/Services is investigating the issue.

Security researcher Laurent Gaffié called Microsoft on the carpet for its Secure Development Lifecycle (SDL) process on Wednesday. Gaffié also published proof-of-concept exploit code that he says will crash both Windows 7 and Windows Server 2008 R2.

"This bug is a real proof that SDL #FAIL," Gaffié wrote in his blog post. "The bug is so noob, it should have been spotted two years ago by the SDL if the SDL had ever existed."

The SMB Relevant Products/Services Flaw

At the core of the vulnerability is the SMB (Server Message Block) protocol, the foundation of Windows file sharing. According to Gaffié, the bug triggers an infinite loop on SMB and can be triggered remotely via Internet Explorer. Gaffié notified Microsoft on Nov. 8 before releasing his proof of exploit on Nov. 11.

When Microsoft released Windows 7 to manufacturing, rumors were rampant about a showstopper bug that could threaten the success of the all-important Vista successor. At that time, technology researchers claimed to have found a bug in the new operating system Relevant Products/Services that causes a massive memory leak and could cause the company to delay the final release. But Microsoft was not able to reproduce the crash.

Other than that, security issues have been nonexistent -- until now. Although Microsoft did have issues with the SMB in the past, security researchers have noted that the SMB vulnerability was difficult to exploit with default firewall conditions. There is a workaround: Blocking ports 135, 139 and 445 on the router or firewall to prevent outside SMB traffic from getting into a system.

Bragging Against Microsoft

Chet Wisniewski, a senior security adviser at Sophos, isn't surprised to see an exploit in Windows 7 so soon after its release. That, he said, is because the Windows code was finalized very early this summer.

"Attackers have had plenty of time to look for holes," Wisniewski said. "This particular flaw was not too difficult to discover, leading the attacker to brag about how stupid it was for Microsoft to have missed it."

At this point, there's no grave danger for Windows 7 users. As Gaffié noted in his disclosure, exploiting the vulnerability can crash a host. That translates to rebooting the computer. Wisniewski noted that the zero-day vulnerability is not in worm form as of yet, and only applies to Windows 7 and Windows 2008 R2. That means it's simply a denial of service Relevant Products/Services at this point.

Will Microsoft issue an out-of-cycle patch? Not unless someone tries to use this to cause a lot of people to complain, Wisniewski said. "The only real way to use it is to spam out a UNC path and trick users into connecting to it," he explained. "It is unlikely, being that no data Relevant Products/Services is lost, and it requires the user to take an action to be affected."

Wisniewski said the author's aggression toward Microsoft is interesting, but aside from that this is simply another everyday denial-of-service vulnerability in Windows.
 

Tell Us What You Think
Your Comment:



Advertisement


 Windows Security
1.   Patch Tuesday Will Tie MS Record
2.   Free Add-On Software for Windows 7
3.   Microsoft Will Issue Patch for IE6
4.   Germany Warns Users Against IE
5.   Oracle, Adobe Patch Vulnerabilities


advertisement
Oracle, Adobe Patch VulnerabilitiesOracle, Adobe Patch Vulnerabilities
Microsoft's Patch Tuesday very light.
Average Rating:
Free Add-On Software for Windows 7Free Add-On Software for Windows 7
Find new tools to enhance functionality.
Average Rating:
Microsoft Will Issue Patch for IE6Microsoft Will Issue Patch for IE6
Upgrading to IE8 is still a good idea.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Mobile Enterprise Spotlight
Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?
 
Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.
 
'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Spam & Hackers | Security Products | Mobile Security | Windows Security | Data Security
EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.