Last Friday, Microsoft published a Security Advisory confirming the existence of a critical vulnerability in all supported versions of Windows. The new zero-day vulnerability is easily exploitable via USB storage devices, network shares or remote WebDAV shares. Also, documents and websites can be crafted as a threat. An exploit targeting this vulnerability is currently in limited use.
Microsoft Advisory: http://www.microsoft.com/technet/security/advisory/2286198.mspx
F-Secure Security Lab is continuing its research into this and the latest news will be available at our blog http://www.f-secure.com/weblog/. More information can also be found in our latest press release at
http://www.f-secure.com/en_EMEA/about-us/pressroom/news/2010/fs_news_20102007_eng.html
The situation has already started to escalate as expected, and the first Malware exploiting this vulnerability is already spreading.
You can find more information here: http://www.f-secure.com/weblog
Therefore it is of utmost important that You check the update status of your systems regularly to ensure you stay protected against any new malware exploiting this vulnerability. This is especially important for systems that are running over long periods of time either without reboot or reduced monitoring, like servers, cash machines and similar.
We have received a few customer reports of F-Secure client and server products not receiving the latest signature updates (http://www.f-secure.com/kb/15444). There have been cases both in 8- and 9-series products.
Should you encounter a computer which hasn’t received updates in the last 48 hours, please try one of the following:
- Press “check now” to enforce signature updates
- Reboot the computer
- Apply the hotfixes available at
http://www.f-secure.com/en_EMEA/support/business/hotfixes/client-security/index.html
http://www.f-secure.com/en_EMEA/support/business/hotfixes/anti-virus-for-citrix-servers/index.html
http://www.f-secure.com/en_EMEA/support/business/hotfixes/anti-virus-for-workstations/index.html
http://www.f-secure.com/en_EMEA/support/business/hotfixes/anti-virus-for-windows-servers/index.html
Please, also apply the Microsoft patch as soon as it is available. We also advise companies to establish a USB Device Policy, review their email attachment policy and to migrate from Windows XP Service Pack 2 to newer versions (SP 3, Windows 7, etc.) as soon as possible.
If the updates don’t start downloading after the actions described above, the problem reappears, or if you have any other questions, please contact our technical support line or any of our team.