Downloader Trojan Exploits Hole in IE 7
Tuesday December 9, 2008 at 7:48 am CST
Posted by Geok Meng Ong and Xiaobo Chen
We have lost count of how many blogs we have written this year that have anything to do with zero-day threats or unpatched vulnerabilities.
Today, many Internet users in China have reported an infection, presumably from browsing the web using a fully patched version of Microsoft Internet Explorer 7.x. My colleague Xiaobo Chen and I investigated the incident and found it to be an active exploit containing downloader shellcode that installs the Downloader-AZN Trojan (proactively detected as New Malware.n since 2005 when scanning with heuristics enabled).
The root cause was found to be the incorrect handling of certain XML tags in Internet Explorer 7.x that references already freed memory in the mshtml.dll.
We have confirmed this vulnerability to be affecting, at least, a fully patched Windows XP SP3 and a Vista SP1 system. The exploit uses publicly known heap-spray techniques that enable control over a vtable pointer, allowing arbitrary code execution.
Fortunately, the 5404 DATs proactively detect the Downloader-AZN Trojan, but there could be other variants. Additional coverage is going into today’s DATs to detect the malicious web scripts as Exploit-XMLhttp.d or Exploit-XMLhttp.c Trojan.
Details about this vulnerability, as well as exploit code, are known to be publicly available.
More information on this situation will be posted as it becomes available.

December 9th, 2008 at 10:42
[...] Zero-day exploit for IE7 Dec.09, 2008 in Security, Short newslinks Just in time for the holidays, a new bug has been found in Internet Explorer that enables hackers to execute arbitrary code. This was first reported by McAfee: [...]
December 10th, 2008 at 03:39
[...] es in der Meldung (externer Link) heißt, hätten zahlreiche in China ansässige Internetsurfer gemeldet, dass auch [...]
December 10th, 2008 at 05:31
[...] wie beispielsweise die von McAfee, haben die Lcke mittlerweile besttigt und warnen vor der Lcke. Gefhrlich wird die Angelegenheit dadurch, dass die Lcke bereits von Angreifern ausgenutzt wird. [...]
December 10th, 2008 at 09:29
[...] McAfee: Downloader Trojan Exploits Hole in IE 7 [...]
December 10th, 2008 at 10:33
[...] should have an alert posted shortly. And here is the link for the Secunia advisory. McAfee has a posting regarding this [...]
December 10th, 2008 at 18:01
[...] http://www.avertlabs.com/research/blog/index.php/2008/12/09/yet-another-unpatched-drive-by-exploit-f... http://www.scanw.com/blog/archives/303 Credit This document was written by Will [...]
December 10th, 2008 at 18:24
[...] SANS Internet Storm Center、McAfee、Secuniaなどの情報を総合すると、脆弱性はXMLタグを処理する際のヒープオーバーフロー問題に起因する。細工を施したHTML文書を使って脆弱性が悪用された場合、任意のコードを実行される恐れがある。[...]
December 10th, 2008 at 18:30
[...] Geok Meng Ong of McAfee’s Avert Labs said “We have confirmed this vulnerability to be affecting, at least, a fully patched Windows XP SP3 and a Vista SP1 system.” The initial exploit uses malformed XML tags to take control of the system, but the problem could be more general, allowing the use of other page elements as attack vectors. [...]
December 11th, 2008 at 05:31
[...] bug è stato identificato da KnowSec nel modo in cui vengono interpretati taluni tag XML e McAfee segnala come in Cina siano gi molti gli utenti infettati da siti aventi pagine maligne appositamente [...]
December 11th, 2008 at 07:46
[...] 7 unter Vista soll die Wirksamkeit des Angriffs laut Microsoft erheblich erschweren. McAfee erwähnt in seinem Blog-Eintrag über den Test des Exploits jedoch keine solche Einschränkung. [...]
December 11th, 2008 at 17:07
[...] Computer Security Research – McAfee Avert Labs Blog [...]
December 17th, 2008 at 04:20
[...] Recently we blogged about an unpatched Internet Explorer 7 exploit in the wild. With the vulnerability information made public, McAfee Avert Labs has noticed a spike [...]
February 8th, 2009 at 09:22
[...] a mitad de diciembre con Explorer y su fallo de seguridad (que incluso provocó una actualización ‘fuera de banda’, algo poco habitual): [...]
PHP has encountered a Stack overflowFebruary 8th, 2009 at 21:03
Recently i downloaded IE8 beta and my KAV says that it infected with trojan…
February 18th, 2009 at 10:36