顯示具有 ZeroDay 標籤的文章。 顯示所有文章
顯示具有 ZeroDay 標籤的文章。 顯示所有文章

2014年10月21日 星期二

注意! ,最新 CVE-2014-4114 PPSX 漏洞已經被利用在攻擊台灣政府單位的APT中 ! Xecure lab discovers new variant of CVE-2014-4114 in Taiwan APT attacks (CVE-2014-4114 with APT Malware Embedded )

打高調廣告先 http://www.ithome.com.tw/news/91439
XecMail 不需要更新就可以偵測到此 APT

最近資安圈很不平靜,很多重大的漏洞一一被挖出來,包含之前在 HITCON Free Talk 介紹到的 Shellshock (直到現在還是很可怕)  , 還有最近 Windows Local 提權,跟今天要分享的 CVE-2014-4114。我們在 10 月 17 號開始在發現很多變種 CVE-2014-4114 已經被用在攻擊台灣政府,以及各單位的 APT Email 中,而且目前掃毒軟體廠商還在悲劇狀態, 要請大家特別注意 !

這個漏洞只會發生在 PPSX 上(也可能在PPTX),利用了 package manager 可以用 INF 安裝東西的功能來實現植入惡意程式,細節請看 MS14-060

可怕的是它利用的一個功能 ("Feature"),而不是什麼 Buffer overrun, 完全不用寫複雜的Shellcode,並可繞過目前資安防禦機制,且穩定又粗暴,可以直接執行任何程式,這是駭客最愛的,而且少數出現專打 Office 2007 之後的 Exploit 。目前 Taidoor 與 LStudio 兩群已經開始用在 APT Email 中,我們預計在半年內都會一直大流行。

惡意等級 : 非常恐怖



2013年11月12日 星期二

[updated: hitting Taiwan too] The recent fresh zero-day targeting Office .docx (CVE-2013-3906)

Watch out~ The recent document exploit CVE-2013-3906 is still a zero-day, it has been over a week, still no patch! By now, we has not witnessed any APT emails hitting Asia carrying this document exploit. However, we believe it's coming soon. [updated] Government agencies in Taiwan are starting to get this document exploit, roughly a week after the security advisory. If you happened to spot any more suspicious ones, feel free to dump to our online XecScan (http://scan.xecure-lab.com), it would digest this document exploit happily, as always.
[This is advertisement] For our XecMail customers, no worry, this zero day would get detected without any engine update. :)

2012年4月16日 星期一

New RTF Exploit CVE-2012-0158 has been discovered in real-world APT attacks!

We have discovered new exploit (CVE-2012-0158) in APT emails!

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0158










This RTF vulnerability was just patched in Apr. 10 as MS12-027.
Microsoft Security Bulletin MS12-027 -
Critical Vulnerability in Windows Common Controls
Could Allow Remote Code Execution (2664258)
http://technet.microsoft.com/en-us/security/bulletin/ms12-027

RTF File:











At this moment, the new exploit enjoys a very low AV detection rate
on VirusTotal, with only 2 out of the 42 antivirus engines flagging it as malicious.

2011年12月11日 星期日

CVE-2011-2462, Xecure Lab 偵測到最新 PDF ZeroDay Exploit

Xecure Lab 領先在傳統防資安設備前,偵測到 CVE-2011-2462 的 U3D 0Day Exploit 樣本正用APT攻擊中 ! 

Xecure Lab 的免費線上APT快篩服務( )
前天捕捉到最新的 PDF 0day Exploit CVE-2011-2462,並且該 Exploit 已經使用在 APT 攻擊中。

(本篇兼賣菜...)