ProSecure™ UTM9S
UTM9S Wins 4/5 Stars & Features NAS Integration
Posted By Netgear Threat Lab at 4:48 PM, July 24, 2009
There have been a number of vulnerabilities discovered in commonly used Web browsers including Internet Explorer and Firefox. A couple of these vulnerabilities have been exploited a lot more than the others:
1. Microsoft Office Web Components Spreadsheet Control zero day vulnerability
The Office Web Components Spreadsheet component is used to publish spreadsheets, forms, and databases to the Web. The security hole allows remote code execution when the victim browses to a Web page that is specifically crafted to exploit the vulnerability. The attacker will then be able to gain complete control of the victim's system. As of now, this security hole is being widely exploited by attackers. Microsoft has published a security bulletin and temporary workaround here:
2. Firefox module allows remote code execution
Mozilla says that the security hole exists in the browser's JavaScript tool called "just in time" in the (JIT) module. Once the module is used, this security hole allows the attacker to execute remote code on the target system and potentially install unwanted software. The Mozilla warns that this vulnerability is already being publicly exploited. More and more users have been on the receiving end of this type of automated virus distribution attack.
In order to prevent the attack, Mozilla has issued the a warning asking users to temporarily stop the use of the browser's JIT module. However, doing so will reduce the browser's JavaScript functionality. Last Thursday, Mozilla released the latest version of Firefox v3.5.1. This version remedied many security holes including this one.
We strongly suggested all users of Firefox either install the update as soon as possible, or disable the JIT module.
Posted by: Netgear Threat Lab at 4:48 PM
Categories: Malware , Netgear Threat Lab
TrackBack URL: http://prosecure.netgear.com/cgi-bin/mt/mt-tb.cgi/36