IE Bug Can Be Exploited Via E-mail

"It might come to nothing, but it feels like a storm's coming," said Roger Thompson, the chief technology officer at Exploit Prevention Labs. "The potential is there. Call it a storm watch, not a storm warning."

At least two different exploits have appeared this week, said Thompson, one linked to the Russian-made hacker exploit kit called WebAttacker, the other posted early Thursday on the xSec gray-hat vulnerability research site. That second exploit can launch remote code without using JavaScript, as did the original inserted in the WebAttacker kit; it's more dangerous for that reason.

"The xSec exploit doesn't work as posted," said Thompson. "It only crashes the browser. But it looks like it would be easy to turn it into a working exploit."

Worse, the current attack vector -- malicious Web sites that infect only those who happen to view one of their pages -- may be replaced by a wide scale attack carried out by e-mail, said Ken Dunham, the director of iDefense's rapid response team.

id
unit-1659132512259
type
Sponsored post

"The newest exploit works with e-mail," said Dunham. "We took the newest version of Outlook, all patched, and the exploit crashed it." With some help from iDefense researchers, however, the exploit was able to execute other code. That means e-mail clients that preview HTML messages using the IE rendering engine are at risk. Just previewing a message could result in a computer hijacked by a bot or loaded with adware, spyware, or other malicious code.

"You would be attacked immediately, as soon as the preview is rendered," said Dunham.

Dunham's surer than Thompson that the VML vulnerability will soon explode. "It's imminent. I would not be surprised if a small number of e-mails were already being sent to companies or governments."

Dunham cited the WMF (Windows Metafile Format) vulnerability of late December 2005 to the current situation. "Within 24 hours, targeted e-mail attacks were made against the Korean government and the U.K. Parliament. I think [the VML vulnerability] will rival WMF." Dunham said. "It's trivial to change."

An e-mail attack was also on Thompson's mind. "I'm watching some big spam runs that are linking to older versions of WebAttacker," he said. "Some of these sites use the power of spam to magnify their attacks, and the power of the Web to draw in people." It would be very easy, Thompson said, for a spammer to simply insert a link to a URL hosting the newest edition of WebAttacker -- the edition with the VML exploit -- in the junk mail he sends out.

"It would be nice if Microsoft released a patch," he added. But there are no indications that Microsoft will break from its regular security update schedule, which is set to release fixes on Oct. 12, two-and-a-half weeks away.

For Dunham, it wouldn't be a stretch to assume that slick, sophisticated cyber criminals will target specific organizations -- companies, universities, and government agencies -- with e-mail infections. "There are people out there with a military or state or political agenda. They have targets, and they've identified those targets. All they're doing is looking for a way to compromise those computers."

The motivation? One of the oldest in the book: Money. "There is a market in the underground for corporate or government secrets," said Dunham. "An attack [like this] could even threaten a country's national security."

Microsoft has faced similar situations this year, and patched out-of-cycle only once, against the WMF bug in early January, and then only after the number of sites hosting an exploit ballooned in just days. "If anything breaks, I think they will release a patch," said Thompson. "But it's not a storm yet."