On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Aug 18, 2005 6:22:00 AM

update Microsoft is investigating a report of a new, unpatched flaw in Internet Explorer that could expose users of the ubiquitous Web browser to attacks.

An attacker could craft a malicious Web site that takes advantage of the flaw and gain control over the PCs that visit the Web site, or an attacker could install malicious software on those systems, a representative of the French Security Incident Response Team said in an e-mail interview Wednesday. The organization rates the issue "critical," its most serious classification.

Exploit code for the flaw is available on the Internet, according to the French security research group. The availability of exploit code typically raises the risk to users because it could aid miscreants in setting up attacks.

Microsoft is investigating the report of the new IE flaw, a company representative said in a statement late Wednesday. The software maker is not aware of attacks that use the reported flaw, the representative said. After the investigation, Microsoft will take the appropriate action to protect users, which could include a security update, she said. The company issued an advisory outlining workarounds for the issue on Thursday.

Internet security monitoring company Websense has added detection mechanisms for this latest potential IE flaw to its software. As of Wednesday afternoon the company had not found any malicious Web sites that take advantage of it, said Dan Hubbard, senior director of security and research at Websense in San Diego.

The flaw is similar to security vulnerabilities Microsoft fixed as part of its monthly patch release last week and in July, according to representative for the French Security Incident Response Team. The problem exists because IE inappropriately lets Web sites instantiate other pieces of Microsoft software on the PC.

It is not clear which users may be at risk. Exploiting this flaw requires a file called "Msdds.dll" to be present on the Windows PC. The French group is still investigating how common that file is. It appears to be installed with Microsoft's Visual Studio developer tools, but it may also be installed with more common software, the group's representative said.

"Microsoft said that this library is installed with Visual Studio, but we do not have Visual Studio installed on our lab machines," the representative said. The group has confirmed the vulnerability on a system with IE 6 on Windows XP with Service Pack 2 and all current patches, this person said.

On Thursday morning, FrSIRT said the exploitable library is also installed with Microsoft Office 2002. "Conclusion: msdds.dll is installed, at least, with Office 2002 and Visual Studio 2002 and 2003," the group said in an e-mail.

Other applications also install the file, the SANS Internet Storm Center said Thursday on its Web site. Applications that may also install this component include Microsoft's .Net Framework 1.1, Office 2000 and Office XP, Project and Visio, the SANS Internet Storm Center said.

IE users can protect themselves by not surfing to untrusted Web sites or disabling ActiveX controls. Using an alternative browser that does not support ActiveX, such as Firefox, also prevents this specific attack, according to SANS and FrSIRT.

Meanwhile, Websense has found Web sites that exploit security flaws Microsoft offered patches for last week and in July. The malicious code embedded in the Web sites installs a backdoor on the computer of the person who visits it with IE on a vulnerable Windows computer, Hubbard said.

There are "a couple of dozen" sites that exploit the IE flaw disclosed last week in Microsoft Security Bulletin MS05-038, according to Websense. The hole fixed with Security Bulletin MS03-037 a month ago is exploited by a couple of hundred Web sites, Hubbard said.

Microsoft rated both those fixed flaws "critical" and has urged users to apply software patches.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 100 Talkback(s)
MSDDS.DLL - Where does it hide?
It would be helpful if the article would include the most common hiding places (drive:\directories) of this file.
Then we wouldn't have to search the entire drive to figure out if we were at risk...... (Read the rest)
Posted by: BandwidthBandit Posted on: 08/21/05 You are currently: a Guest | | Terms of Use
malicious software  trm1945 | 08/17/05
re: malicious software  bugmenotznet | 08/18/05
Malicious software  fwright | 08/18/05
I'm in the process of  Real World | 08/18/05
YMMV  Yagotta B. Kidding | 08/18/05
This is an area where Apple really has it right...  BitTwiddler | 08/18/05
Amen!  Nullifidian | 08/18/05
Actually  IT Scion | 08/18/05
Vista = DOA  ITGuy04 | 08/18/05
You are so wrong!  ShadeTree | 08/18/05
Wait a minute  Rick_K | 08/18/05
so right  ITGuy04 | 08/19/05
Re: so right  Anti_Zealot | 08/19/05
One step further  Yagotta B. Kidding | 08/18/05
wow, i never tried...  linuxoverwindows | 08/18/05
It can be handy  Yagotta B. Kidding | 08/18/05
Root  Immanuel Tranz-Mischen | 08/20/05
You are correct  IT Scion | 08/18/05
That would be inconvenient  Yagotta B. Kidding | 08/18/05
as more and more  linuxoverwindows | 08/18/05
Message has been deleted.  realitycheck101 | 08/18/05
You, sir, are an idiot.  ObiWayneKenobi | 08/18/05
Pot Kettle Black?  Rick_K | 08/18/05
but his post!!!11oneone  linuxoverwindows | 08/18/05
Like your company is any better.  bhodges00 | 08/18/05
lmao!1one  linuxoverwindows | 08/18/05
WAAAAAH!  Real World | 08/18/05
You know what would be really cool ....  dstinson_z | 08/18/05
what i found funny about the article...  linuxoverwindows | 08/18/05
A Flaw In IE  railroads99 | 08/18/05
What are you rambling about?  dstinson_z | 08/18/05
gas prices lol  linuxoverwindows | 08/18/05
Another peek in Microsoft's Linux lab  whisperycat | 08/18/05
LMAO 9.00  archnova79 | 08/18/05
Microsoft investigates potential new IE flaw  Loverock Davidson | 08/18/05
Agree with your first 3 sentences  Michael Kelly | 08/18/05
Good, at least we agree on something (NT)  Loverock Davidson | 08/18/05
Shill...  jasonp@... | 08/18/05
Ah crap, you again?  Loverock Davidson | 08/18/05
Which version was that?  Anti_Zealot | 08/18/05
wouldn't get your hopes up for a response  Monkey_MCSE | 08/18/05
I would  Loverock Davidson | 08/18/05
Please do, it would be helpful (nt)  Anti_Zealot | 08/18/05
So where is that link?  Monkey_MCSE | 08/18/05
Linux users...  jasonp@... | 08/19/05
FS corruption  Yagotta B. Kidding | 08/18/05
Thank you very much  Anti_Zealot | 08/18/05
He's not any worse than you  bhodges00 | 08/18/05
It just cost money  Hanover Phist | 08/18/05
if it's worth it  bhodges00 | 08/18/05
You really  Rick_K | 08/18/05
No you do  Loverock Davidson | 08/18/05
Get Real  Rick_K | 08/18/05
my god, actual facts  Monkey_MCSE | 08/18/05
Facts?  Loverock Davidson | 08/18/05
and where were these facts?  Monkey_MCSE | 08/18/05
and where were these facts?  Loverock Davidson | 08/18/05
Let me get that straight: you are insulted when you see others  michael_t | 08/19/05
You get real  Loverock Davidson | 08/18/05
Let's Try the NIST Database for Facts  PMC-CON | 08/18/05
Sequence counts  Yagotta B. Kidding | 08/18/05
Which is your true name?  jolumoar | 08/18/05
IE  railroads99 | 08/18/05
Take Responsibility For Yourself  nuttygardener | 08/18/05
HAHA, Bill G. got your money, and I am going to the beach  educateme@... | 08/18/05
Amen!  An_Axe_to_Grind | 08/18/05
sip 2 for me.  linuxoverwindows | 08/18/05
Oh I didn't know Apple and Linux don't need patches.  bhodges00 | 08/18/05
ummm so you know  Monkey_MCSE | 08/18/05
like everybody has broadband  bhodges00 | 08/18/05
Backward countries  Yagotta B. Kidding | 08/18/05
how many home users  Monkey_MCSE | 08/18/05
bs yourself  bhodges00 | 08/18/05
CAD options -Ashlar Vellum for OSX, & it reads DXF  educateme@... | 08/18/05
sorry to burst your bubble  bhodges00 | 08/18/05
this is what i read...  linuxoverwindows | 08/18/05
It's an IQ test...  gfeier | 08/18/05
It's an IQ test  big-skip@... | 08/18/05
i believe maxthon  Monkey_MCSE | 08/18/05
correct  nuttygardener | 08/19/05
every software is flawed  bhodges00 | 08/18/05
Not as flawed as Microsoft  MacCanuck | 08/19/05
waaa  bhodges00 | 08/19/05
"waaa"... the extent of your vocabulary... figures  MacCanuck | 08/19/05
They?  Yagotta B. Kidding | 08/18/05
to loverock with love  Monkey_MCSE | 08/18/05
You love me  Loverock Davidson | 08/18/05
MSDSS.DLL -- Not Found on XP with VS 98, 2002, 2003  PMC-CON | 08/18/05
It's MSDDS.DLL...  rapson | 08/18/05
Thanks  PMC-CON | 08/18/05
Of course, name mistyped - sigh - senility is hard sometimes.  PMC-CON | 08/18/05
Probably neither  rapson | 08/18/05
I Think I recognize your name ...  PMC-CON | 08/18/05
Dunno  rapson | 08/18/05
I searched too...  DragonBRockin | 08/18/05
More flaws?  jolumoar | 08/18/05
Flaw only affects Windows if your running...  DragonBRockin | 08/18/05
Just the link where I got my Info...  DragonBRockin | 08/18/05
Microsoft Transcript Of IE Flaw Investigation  itanalyst | 08/19/05
MSDDS.DLL - Where does it hide?  BandwidthBandit | 08/21/05

What do you think?

advertisement
Click Here
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here