Microsoft Airs Temporary Fix to Defeat Duqu Worm
November 4, 2011 4:00 PM
comment(s) - last by
Worm is exploiting zero-day exploit in the TrueType Windows component
The Duqu [dyü-kyü] worm
, containing parts of
the Stuxnet code
, is a sophisticated piece of malware that's wreaking havoc on Windows machines worldwide. The authors appear to be specially targeting business and governmental entities in what may be a cyberespionage or cybersabotage attempt.
A Fix for Duqu:
Duqu is essentially the precursor to a future Stuxnet-like attack. The threat was written by the same authors, or those that have access to the Stuxnet source code, and the recovered samples have been created after the last-discovered version of Stuxnet. Duqu’s purpose is to gather intelligence data and assets from entities such as industrial infrastructure and system manufacturers, amongst others not in the industrial sector, in order to more easily conduct a future attack against another third party. The attackers are looking for information such as design documents that could help them mount a future attack on various industries, including industrial control system facilities.
The malware piggybacks inside seemingly legitimate documents from Microsoft Corp.'s (
) Word application. Once infected, the malware takes complete control of the affected system and accesses the address book, sending out infected Word documents to your contacts along with brief, innocuous seeming messages. Microsoft listed the threat as "severe".
Usually Microsoft has a pretty fast turnaround, when it comes to addressing such serious threats, and it did not disappoint here. Just days after the zero-day vulnerability was discovered, Microsoft has published new details of what's going on, along with a temporary fix to remove Duqu.
Microsoft's TechNet Security TechCenter and
in the Microsoft Knowledge Base the Duqu virus is exploiting a zero-day vulnerability in the Win32k TrueType font-parsing engine. The vulnerability allows arbitrary code to be executed in kernel mode (a so called "privileges escalation" exploit).
A peak at the code of Duqu's malware payload [Source: Symantec]
Microsoft has also released a QuickFix tool, available in the above linked Knowledge Base post, which scrounges around and removes the vestiges of known Duqu variants
Symantec Corp. (
) -- one of the world's largest security firms -- is currently working with Microsoft to combat the threat and identify variants of the growing malware threat. The company has published a detailed report on Duqu, which is available
Symantec has chronicled Duqu's sophisticated remote command & control (CaC) scheme. [Source: Symantec]
Symantec researchers say they first received a copy of Duqu from the
Budapest University of Technology and Economics
(BME). BME obtained that piece on Oct. 14.
Some argue that Microsoft
rushes patches for vulnerabilities to market too fast
. They say that rushed patches often fail to completely protect against various variants of a malware threat, hurting the user in the long run. Still, the majority of security firms seem supportive of Microsoft's approach.
In related news chipmaker Intel Corp. (
) is working with recent acquisition McAfee to include
hardware-level protection against escalation of privileges attacks
. The technology seems very promising as it could protect against so-called zero-day vulnerabilities like the TrueType parsing exploit used by Duqu. While it might seem improbable to be able to protect against an attack you've never encountered before, Intel is looking to do this by detecting the kinds of escalation behavior that are ubiquitous among many malware programs.
This article is over a month old, voting and posting comments is disabled
11/4/2011 5:27:41 PM
The vulnerability cannot be exploited automatically through e-mail. For an attack to be successful,
a user must open an attachment that is sent in an e-mail message
"My sex life is pretty good" -- Steve Jobs' random musings during the 2010 D8 conference
Nasty "Duqu" Worm Exploits Same Microsoft Office Bug as Stuxnet
November 2, 2011, 12:32 PM
Intel Gets EU Approval to Purchase McAfee
January 28, 2011, 9:16 AM
Israel Suspected in Worm Sabotage of Iran's First Nuclear Plant
September 27, 2010, 10:45 AM
Debate Continues Over Whether Microsoft Should Hurry Patches for Vulnerabilities
December 29, 2008, 12:31 PM
Google Engineer Finds Microsoft Security Flaw, Says Company is Hostile About It
May 23, 2013, 10:51 AM
Survey: 94 Percent of Teens Use Facebook
May 22, 2013, 2:53 PM
Congress Looks to Force Extra Protection on Utilities to Combat Cyberattacks
May 22, 2013, 2:24 PM
U.S. Military Cuts Guantanamo Bay Wi-Fi After Alleged Threat by Anonymous
May 21, 2013, 11:00 AM
Yahoo Acquires Tumblr for $1.1 Billion
May 20, 2013, 11:12 AM
Newegg Legal Chief: "We don't Feed the Trolls"; Defeats Bell Lab Shell Comp.
May 17, 2013, 10:11 AM
Most Popular Articles
High School Student Creates Storage Device that Can Charge in 20 Seconds
May 20, 2013, 6:51 AM
NASA Awards $125,000 Grant for 3D Printed Food on Long-Term Space Travels
May 21, 2013, 1:32 PM
Seawater Cooling Saves Data Center Big Bucks, Energy, Despite Jellyfish Issues
May 17, 2013, 3:23 PM
Microsoft Announces Voice-Controlled "Xbox One"
May 21, 2013, 12:55 AM
EA Dev: Nintendo is "the Walking Dead"; Wii U is "Crap"
May 20, 2013, 11:27 AM
Latest Blog Posts
Lumosity: Does it Work?
May 22, 2013, 8:20 PM
Quick Note: Sony "Teases" PS4 Ahead of Xbox Reveal in New Video
May 20, 2013, 12:33 PM
Nokia Introduces Instagram-Like App of Its Own to Help Lumia Sales
May 20, 2013, 7:10 AM
Parents of Pre-Teen Drivers Commonly Practice Distracted Driving Says Study
May 9, 2013, 7:16 AM
Apple's iOS 7 Running Into Internal Delays Due to Massive Overhaul
May 1, 2013, 4:26 PM
More Blog Posts
Copyright 2013 DailyTech LLC. -
Terms, Conditions & Privacy Information