Matsuda Posted November 7, 2013 Share Posted November 7, 2013 (edited) Microsoft found a major vulnerability flaw in Windows and Office that allows attackers to get the same privileges as the logged on user with the help of a compromised document.Security institute AV-TEST analyzed three different malicious DOCX files used to exploit the vulnerability, determining that some of the anti-virus products on the market are already capable of protecting their users.As a result, consumers are strongly recommended to update their security apps to make sure that no attack is targeting their computers until Microsoft rolls out a fully working patch for the flaw.The following vendors have already released publicly available (static) detection signatures in their anti-malware products to protect against these known malicious files:Avast -> TIFF:CVE-2013-3906 [Expl]AVG -> Exploit_c.YWT (Trojan horse)Bitdefender -> Exploit.CVE-2013-3906.GenESET NOD32 -> Win32/Exploit.CVE-2013-3906.A trojanF-Secure -> Exploit.CVE-2013-3906.GenG Data -> Exploit.CVE-2013-3906.GenKaspersky -> Exploit.MSOffice.CVE-2013-3906.a, Exploit.OLE2.CVE-2012-1856.bMicrosoft -> Exploit:Win32/CVE-2013-3906Norman -> Shellcode.B, Shellcode.DNorton -> Trojan.Hantiff, Trojan.MdropperSophos -> Exp/20133906-A, Troj/DocDrop-APUPDATE! 2013-11-08, AV-TEST has identified further samples and analyzed them now. We are currently aware of 8 different malicious DOCX files containing the CVE-2013-3906 exploit. The following AV products are able to detect all of these samples using (static) signatures:AhnLab -> Exploit/Cve-2013-3906AVG -> Exploit_c.YWS, Exploit_c.YWTAvast -> TIFF:CVE-2013-3906 [Expl]Avira -> EXP/CVE-2013-3906Bitdefender -> Exploit.CVE-2013-3906.GenClamAV -> Win.Exploit.CVE_2013_3906-2, BC.Exploit.CVE_2013_3906.CVE_2013_3906ESET NOD32 -> Win32/Exploit.CVE-2013-3906.AF-Secure -> Exploit.CVE-2013-3906.GenG Data -> Exploit.CVE-2013-3906.GenKaspersky -> Exploit.MSOffice.CVE-2013-3906.a, Exploit.OLE2.CVE-2012-1856.bMcAfee -> Exploit-CVE2013-3906Microsoft -> Exploit:Win32/CVE-2013-3906Norman -> Shellcode.B, Shellcode.DNorton -> Trojan.Hantiff, Trojan.MdropperUPDATE! 11.11.2013Ahnlab -> Exploit/Cve-2013-3906 Avast -> TIFF:CVE-2013-3906 [Expl] AVG -> Exploit_c.YWS, Exploit_c.YWT Avira -> EXP/CVE-2013-3906, EXP/CVE-2013-3906.A Bitdefender -> Exploit.CVE-2013-3906.Gen Commtouch / F-Prot -> CVE133906 Dr.Web -> Exploit.CVE2013-3906.1, Exploit.CVE2013-3906.2 ESET NOD32 -> Win32/Exploit.CVE-2013-3906.A trojan Fortinet-> W32/DocDrop.AP!tr, W32/MSOffice_CVE_2013_3906.A!exploit F-Secure -> Exploit.CVE-2013-3906.Gen G Data -> Exploit.CVE-2013-3906.Gen Kaspersky -> Exploit.MSOffice.CVE-2013-3906.a, Exploit.OLE2.CVE-2012-1856.b McAfee -> Exploit-CVE2013-3906 (trojan), Exploit-FMC!DE64624613FD (trojan) Microsoft -> Exploit:Win32/CVE-2013-3906 Norman -> Shellcode.B, Shellcode.D Norton -> Trojan.Hantiff, Trojan.Mdropper Sophos -> Troj/DocDrop-AP ThreatTrack -> Exploit.TIFF.CVE-2013-3906 (v)Note: Products / vendors not listed are either not yet tested or won't provide a full coverage yet (e.g. they are only detecting some but not all of the samples).View: Original Article Edited November 11, 2013 by Matsuda Link to comment Share on other sites More sharing options...
AlexCross Posted November 7, 2013 Share Posted November 7, 2013 Mhhh, so Avira is that bad? It used to be good. So Mcafee, Link to comment Share on other sites More sharing options...
Matsuda Posted November 7, 2013 Author Share Posted November 7, 2013 Mhhh, so Avira is that bad? It used to be good. So Mcafee,Products / vendors not listed are either not yet tested or won't provide a full coverage yet (as of 2013-11-07 10:30 UTC). We plan to update the list from time to time as soon as new updates have been released. https://www.facebook.com/avtestorg/posts/646110562108402 :) Link to comment Share on other sites More sharing options...
nIGHT Posted November 8, 2013 Share Posted November 8, 2013 affected Wind0ws version and office version? :rolleyes:wind0ws 8.1 and its 0ffice 2013 is also vulnerable? :rolleyes: Link to comment Share on other sites More sharing options...
manju Posted November 8, 2013 Share Posted November 8, 2013 it's a word file so it's possible to be cross-platform regargind office suites :unsure: Link to comment Share on other sites More sharing options...
Matsuda Posted November 8, 2013 Author Share Posted November 8, 2013 (edited) wind0ws 8.1 and its 0ffice 2013 is also vulnerable? :rolleyes: :uhuh:, Windows Vista, Windows Server 2008, Microsoft Office 2003 through 2010 and Microsoft Lync. :) Edited November 8, 2013 by Matsuda Link to comment Share on other sites More sharing options...
Matsuda Posted November 8, 2013 Author Share Posted November 8, 2013 Updated. :) Link to comment Share on other sites More sharing options...
AlienForce1 Posted November 9, 2013 Share Posted November 9, 2013 http://blogs.technet.com/b/srd/archive/2013/11/05/cve-2013-3906-a-graphics-vulnerability-exploited-through-word-documents.aspxOther layers of defense : Link to comment Share on other sites More sharing options...
Matsuda Posted November 9, 2013 Author Share Posted November 9, 2013 Yes @AlienForce1, was confirmed today, Windows XP also affected. ;) Link to comment Share on other sites More sharing options...
Recommended Posts