<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security Research &amp; Defense</title><link>http://blogs.technet.com/srd/default.aspx</link><description>Information from Microsoft about vulnerabilities, mitigations and workarounds, active attacks, security research, tools and guidance &lt;br&gt;&lt;br&gt; MSRC Engineering &amp; MSEC Science</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Assessing the risk of the February Security Bulletins</title><link>http://blogs.technet.com/srd/archive/2010/02/09/assessing-the-risk-of-the-february-security-bulletins.aspx</link><pubDate>Tue, 09 Feb 2010 18:05:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3311630</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3311630.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3311630</wfw:commentRss><description>&lt;p&gt;This morning, we released &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS10-feb.mspx" mce_href="http://www.microsoft.com/technet/security/Bulletin/MS10-feb.mspx"&gt;13 security bulletins.&lt;/a&gt;&amp;nbsp;
Five have maximum severity rating of Critical, seven Important, and one
Moderate. One security bulletin (&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-015.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-015.mspx"&gt;MS10-015&lt;/a&gt;, ntvdm.dll) has exploit code
already published, but we are not aware of any active attacks or
customer impact. We hope that the table and commentary below helps you
prioritize the deployment of the updates appropriately.&lt;/p&gt;

&lt;table border="1"&gt;
&lt;tbody&gt;&lt;tr valign="top"&gt;
&lt;td width="74"&gt;
&lt;b&gt;Bulletin&lt;/b&gt;
&lt;/td&gt;

&lt;td class="gen262237" width="92"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-weight: bold;"&gt;Most likely attack vector&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238" width="56"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-weight: bold;"&gt;Max Bulletin Severity&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239" width="52"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-weight: bold;"&gt;Max Exploit- ability Index&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240" width="126"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-weight: bold;"&gt;Likely first 30 days impact&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241" width="85"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-weight: bold;"&gt;Platform mitigations&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-013.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-013.mspx"&gt;MS10-013&lt;/a&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;(Quartz)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Victim opens malicious AVI or WAV file. &lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Critical&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;1&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Likely to see working exploit in next 30 days.&amp;nbsp; &lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-007.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-007.mspx"&gt;MS10-007&lt;/a&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;(ShellExecute)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attacker hosts a malicious webpage, lures victim to it.&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Critical&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;1&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Likely to see exploit code released resulting in binary on WebDAV share being executed.&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;For more detail, see this &lt;a href="http://blogs.technet.com/srd/archive/2010/02/09/ms10-007-additional-information-and-recommendations-for-developers.aspx" mce_href="http://blogs.technet.com/srd/archive/2010/02/09/ms10-007-additional-information-and-recommendations-for-developers.aspx"&gt;SRD blog post&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-006.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-006.mspx"&gt;MS10-006&lt;/a&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;(SMB Client)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Local&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt;ly logged-in attacker with low privilege runs a malicious executable to elevate to high privilege.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Critical&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;1&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Likely to see &lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt;
working exploit code for local attacker escalation.&lt;/span&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;For more detail, see this &lt;a href="http://blogs.technet.com/srd/archive/2010/02/09/ms10-006-and-ms10-012-smb-security-bulletins.aspx" mce_href="http://blogs.technet.com/srd/archive/2010/02/09/ms10-006-and-ms10-012-smb-security-bulletins.aspx"&gt;SRD blog post&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-001.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-001.mspx"&gt;MS10-008&lt;/a&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;(ActiveX kill-bits)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attackers host a malicious webpage, lures victim to it&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Critical&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;2&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Likely to see working exploit for vulnerabilities in third party ActiveX controls.&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-012.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-012.mspx"&gt;MS10-012&lt;/a&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;(SMB Server)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attacker sends network-based malicious connection to remote Windows machine via SMB.&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Important&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;1&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Likely to see working proof-of-concept in next 30 days for CVE-2010-0231 resulting in attacker
&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt;
luring remote victim user to open file on attacker server and
initiating a connection back to machine where remote victim is logged
on.&amp;nbsp;
&lt;/span&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;Less
likely to see working exploit code for the authenticated code execution
vulnerability (CVE-2010-0020) or unauthenticated denial-&lt;span class="Table_0020Grid__Char" style="font-size: 11pt;"&gt;of-service
 vulnerabilities (CVE-2010-0021 and 0022)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;For more detail, see this &lt;a href="http://blogs.technet.com/srd/archive/2010/02/09/ms10-006-and-ms10-012-smb-security-bulletins.aspx" mce_href="http://blogs.technet.com/srd/archive/2010/02/09/ms10-006-and-ms10-012-smb-security-bulletins.aspx"&gt;SRD blog post&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-015.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-015.mspx"&gt;MS10-015&lt;/a&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;(Kernel)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attacker already able to execute code as low-privileged user escalates&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt; privileges.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Important&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;1&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Proof of concept code already widely available&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt;. No active attacks.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-011.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-011.mspx"&gt;MS10-011&lt;/a&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;(CSRSS)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attacker &lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt;
who logs onto console of system where victim later logs onto console of
same system can potentially run code with victim’s identity.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Important&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;1&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Likely to see &lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt;
proof-of-concept code published for this vulnerability.&amp;nbsp; However,
unlikely to see wide-spread exploitation due to extensive user
interaction required.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-009.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-009.mspx"&gt;MS10-009&lt;/a&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;(TCP/IP)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attacker sends network-based attack against system on local subnet.&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Critical&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;2&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;May see denial-of-service proof-of-concept
code published leveraging CVE-2010-0239 or CVE-2010-0241.&amp;nbsp; Attackers
are less likely to discover real-world attack surface in next 30 days
for CVE-2010-0240.&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;
&lt;p class="Table_0020Grid"&gt;/GS effective mitigation for CVE’&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;s:&lt;/span&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;CVE-2010-0239&lt;/span&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;CVE-2010-0240&lt;/span&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;CVE-2010-0241.
&lt;/span&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;CVE-2010-0242 is denial of service only.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-003.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-003.mspx"&gt;MS10-003&lt;/a&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;(Excel)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attack sends malicious .xls file to victim who opens it with Office XP or lower.&amp;nbsp; (Office 2003, 2007 not affected.)&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Important&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;1&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Likely to see working exploit file effective on Office XP in first 30 days.&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;
&lt;p class="Table_0020Grid"&gt;Office 2003 and Office 2007 not affected.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-004.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-004.mspx"&gt;MS10-004&lt;/a&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;(PowerPoint)&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attacks malicious .ppt file to victim who opens it with Powerpoint Viewer 2003.&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Important&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;1&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Likely to see working exploit file effective
on PowerPoint Viewer 2003.&amp;nbsp; However, PowerPoint Viewer 2003 was
replaced online by PowerPoint Viewer 2007.&amp;nbsp; Only victims who use
&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt;
PowerPoint Viewer 2003 from Office 2003 install disk would be vulnerable to the PowerPoint Viewer vulnerabilities.&amp;nbsp;
&lt;/span&gt;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Table_0020Grid"&gt;&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial';"&gt;Less likely to see work&lt;span class="Table_0020Grid__Char" style="font-size: 11pt;"&gt;ing exploit for other PowerPoint vulnerabilities.
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-010.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-010.mspx"&gt;MS10-010&lt;/a&gt;&lt;/p&gt;&lt;p class="Table_0020Grid"&gt;(Hyper-V) &lt;br&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attacker running code on virtual machine crashes host OS&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Important&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;3&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Unlikely to see working exploit code&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt; in next 30 days.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-014.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-014.mspx"&gt;MS10-014&lt;/a&gt;&lt;/p&gt;&lt;p class="Table_0020Grid"&gt;(Kerberos) &lt;br&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attacker potentially able to cause denial of service via
&lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt;
Kerberos traffic if victim server configured with trust relationship to MIT Kerberos realm.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Important&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;3&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Unlikely to see public exploit code &lt;span class="Table_0020Grid__Char" style="font-family: 'Calibri','Arial'; font-size: 11pt;"&gt;
in next 30 days.&lt;/span&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;

&lt;tr valign="top"&gt;
&lt;td class="gen262236"&gt;
&lt;p class="Table_0020Grid"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-005.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-005.mspx"&gt;MS10-005&lt;/a&gt;&lt;/p&gt;&lt;p class="Table_0020Grid"&gt;(GDI+) &lt;br&gt;&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262237"&gt;
&lt;p class="Table_0020Grid"&gt;Attacker sends malicious JPEG to victim.&amp;nbsp;&amp;nbsp; Victim saves JPG, launches mspaint, and then file-&amp;gt;opens the malicious JPEG&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262238"&gt;
&lt;p class="Table_0020Grid"&gt;Moderate&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262239"&gt;
&lt;p class="Table_0020Grid"&gt;1&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262240"&gt;
&lt;p class="Table_0020Grid"&gt;Likely to see exploit code developed.&amp;nbsp; Unlikely to have broad impact as mspaint is not registered file association for JPEG.&lt;/p&gt;
&lt;/td&gt;

&lt;td class="gen262241"&gt;&amp;nbsp;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p class="Normal"&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="Normal"&gt;We also released &lt;a href="http://www.microsoft.com/technet/security/advisory/977377.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/977377.mspx"&gt;Security Advisory 977377&lt;/a&gt;
covering the TLS man-in-the-middle vulnerabilities disclosed several
months ago.&amp;nbsp; The advisory describes more about the Microsoft attack
surface (and a mitigation option).&amp;nbsp; You can read our blog post about
the issue here: &lt;a href="http://blogs.technet.com/srd/archive/2010/02/09/details-on-the-new-tls-advisory.aspx" mce_href="http://blogs.technet.com/srd/archive/2010/02/09/details-on-the-new-tls-advisory.aspx"&gt;http://blogs.technet.com/srd/archive/2010/02/09/details-on-the-new-tls-advisory.aspx&lt;/a&gt;.&lt;/p&gt;

&lt;p class="Normal"&gt;Thanks to all of MSRC Engineering for providing data
for this table.&amp;nbsp; Thanks Jerry Bryant, Andrew Roths, and Mark Wodrich
for your ordering / priority thoughts.&lt;/p&gt;

&lt;p class="List_0020Paragraph" style="text-indent: -18pt;"&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Jonathan Ness, MSRC Engineering&lt;/p&gt;&lt;p&gt;*Posting is provided "AS IS" with no warranties, and confers no rights.*&lt;/p&gt;&lt;p class="List_0020Paragraph" style="text-indent: -18pt;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3311630" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/Mitigations/default.aspx">Mitigations</category><category domain="http://blogs.technet.com/srd/archive/tags/rating/default.aspx">rating</category><category domain="http://blogs.technet.com/srd/archive/tags/Exploitability/default.aspx">Exploitability</category><category domain="http://blogs.technet.com/srd/archive/tags/Risk+Asessment/default.aspx">Risk Asessment</category></item><item><title>MS10-007: Additional information and recommendations for developers</title><link>http://blogs.technet.com/srd/archive/2010/02/09/ms10-007-additional-information-and-recommendations-for-developers.aspx</link><pubDate>Tue, 09 Feb 2010 18:01:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3311591</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3311591.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3311591</wfw:commentRss><description>&lt;p&gt;Today we are releasing &lt;a href="http://www.microsoft.com/technet/security/bulletin/MS10-007.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-007.mspx"&gt;MS10-007&lt;/a&gt; to address a URL validation issue generally applicable to the ShellExecute API.&lt;/p&gt;

&lt;p&gt;&lt;b&gt;How would a malicious user leverage this vulnerability?&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;This issue involves how ShellExecute handles strings that appear to be legitimate URLs, but are malformed such that they result in execution of arbitrary code.  Various technologies use ShellExecute to initiate a browser navigation.  It is assumed that the operation is safe if the parameter passed to ShellExecute “looks like a URL.” It seems reasonable to expect that if a string is a valid URL, it cannot possibly result in execution of arbitrary code when processed by ShellExecute.&lt;/p&gt;

&lt;p&gt;But while it may be valid to assume that &lt;/p&gt;
&lt;pre&gt;ShellExecute(URL)&lt;/pre&gt; will not execute a system command, it should be understood that the core purpose of the ShellExecute API is to execute files.  This vulnerability involves the use of a valid-looking URL that ShellExecute will run as a system command.  To get exploited, a user might click on a link appearing outside the context of the browser, for example as an address book contact.  At that point, a remote executable could run without prompting.

&lt;p&gt;&lt;b&gt;Recommendations for Developers&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;We recommend that application developers wishing to use ShellExecute for URL-based navigation take a conservative approach to validation.  First, developers should heed the specific guidance in &lt;a href="http://support.microsoft.com/kb/943522" mce_href="http://support.microsoft.com/kb/943522"&gt;KB943552&lt;/a&gt; as it pertains to this scenario.  Additionally, rather than simply validating that a URL is of the format [scheme]://[FQDN]/[path]?[querystring], it is advisable to also validate that the URL scheme is one of a specific set of allow-listed URL schemes, for example “http” or “https.”  This is consistent with guidance provided in Chapter 4 of the &lt;a href="http://msdn.microsoft.com/en-us/library/aa302420.aspx" mce_href="http://msdn.microsoft.com/en-us/library/aa302420.aspx"&gt;Microsoft Design Guidelines for Secure Web Applications&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;As it turns out, many commonly-used code paths actually do perform this level of URL scheme validation and thus do not present viable attack vectors, even in the presence of the ShellExecute bug.  Defense-in-depth FTW!&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Acknowledgements&lt;/b&gt;&lt;br&gt;
Thanks to Chengyun Chu for insight and analysis on this issue.&lt;/p&gt;

&lt;p&gt;- David Ross, MSRC Engineering&lt;/p&gt;&lt;p&gt;*Posting is provided "AS IS" with no warranties, and confers no rights.*&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3311591" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/Defense-in-depth/default.aspx">Defense-in-depth</category><category domain="http://blogs.technet.com/srd/archive/tags/ShellExecute/default.aspx">ShellExecute</category></item><item><title>MS10-006 and MS10-012: SMB security bulletins</title><link>http://blogs.technet.com/srd/archive/2010/02/09/ms10-006-and-ms10-012-smb-security-bulletins.aspx</link><pubDate>Tue, 09 Feb 2010 18:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3311596</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3311596.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3311596</wfw:commentRss><description>&lt;P&gt;Today we released two bulletins to address vulnerabilities in SMB. &lt;A href="http://www.microsoft.com/technet/security/bulletin/MS10-006.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-006.mspx"&gt;MS10-006&lt;/A&gt; addresses two vulnerabilities in the SMBv1&lt;B&gt; &lt;U&gt;client&lt;/U&gt;&lt;/B&gt; implementation, and &lt;A href="http://www.microsoft.com/technet/security/bulletin/MS10-012.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-012.mspx"&gt;MS10-012 &lt;/A&gt;addresses four vulnerabilities in the SMB&lt;B&gt; &lt;U&gt;server&lt;/U&gt;&lt;/B&gt; implementation. In this blog entry, we want to help you understand the vulnerabilities and better prioritize the updates.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;What are the SMB server vulnerabilities and how could they be exploited?&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The first issue is an authenticated remote code execution (RCE) vulnerability (CVE-2010-0020) in the server SMBv1 implementation on all versions of Windows. A long filename can lead to kernel pool memory corruption in an error path. This issue has a severity rating of important as an attacker needs to be authenticated to perform the attack.&lt;/P&gt;
&lt;P&gt;The second and third issues (CVE-2010-0021 and CVE-2010-0022) are remote unauthenticated denial-of-service (DoS) vulnerabilities in the SMBv1 and SMBv2 server implementations and have&amp;nbsp;Important severity ratings. CVE-2010-0021 is caused by a race condition when handling valid Negotiate requests. CVE-2010-0022 is caused by an integer underflow when handling a path name in the SMB request.&lt;/P&gt;
&lt;P&gt;The final server-side issue is CVE-2010-0231, an Important-severity remote unauthenticated elevation of privilege (EoP) affecting all versions of Windows. This issue is unusual in that it is caused by weak entropy in the cryptographic challenge values generated by SMB. An attacker could exploit this issue and gain access to the SMB server under the credentials of an authorized user. &lt;/P&gt;
&lt;P&gt;We recommend placing higher priority on&amp;nbsp;the SMB server-side update due to the risk of RCE and EoP on all systems.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;What are the SMB client vulnerabilities?&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The first issue is a Critical severity kernel pool memory corruption vulnerability (CVE-2010-0016) in the client SMBv1 implementation on Windows 2003 and below. The vulnerability happens during the SMB client/server negotiation phase and&amp;nbsp; does not require authentication. A remote attacker who successfully exploits this issue could gain complete control of the target system.&lt;/P&gt;
&lt;P&gt;The second one is an Important severity&amp;nbsp;race condition in the client SMBv1 code on Windows Vista and higher (CVE-2010-0017). The vulnerability&amp;nbsp;is in&amp;nbsp;the SMB client/server negotiation phase and does not require authentication. The severity of this issue depends on the version of Windows on the client computer: &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;On Windows Vista and Windows Server 2008 a remote attacker would not be able to gain control of a target system using this vulnerability; instead the impact would be a system DoS. However, a local authenticated user could potentially exploit this vulnerability and gain control of the system. On these platforms, the severity of this issue is Important. The update should be prioritized for Terminal Servers and other system that allow users to log on locally.&lt;/LI&gt;
&lt;LI&gt;On Windows 7 and Windows Server 2008 R2 a remote attacker can potentially gain control of a target system using a variation of this vulnerability. Due to the RCE impact, the severity of this issue on these platforms&amp;nbsp;is Critical. Unsuccessful attempts to exploit the vulnerability would result in a system DoS. This update should be applied to all affected systems due to the RCE risk; however, due to the nature of the issue, DoS is much more likely.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;B&gt;Why does the SMB client update have an aggregate severity of Critical on Windows 7 and Windows Server 2008 R@, but only Important on Vista and Windows Server 2008?&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;As outlined above, CVE-2010-0017 affects Vista and higher systems and is rated Important on Vista and Windows Server 2008. However, on Windows 7 and Windows Server 2008 R2, the severity is higher (Critical) due to the risk of RCE. The reason for this difference is a design change made during the Windows 7 development process, when the SMB client code moved to use a new kernel-mode networking I/O mechanism – &lt;A href="http://blogs.msdn.com/wndp/archive/2006/02/24/538746.aspx" mce_href="http://blogs.msdn.com/wndp/archive/2006/02/24/538746.aspx"&gt;Winsock Kernel (WSK)&lt;/A&gt;. This change exposed the SMB client code to different timing conditions, exposing a race condition. This race condition is different to the issue present on Vista and Windows Server 2008, although it is reachable under similar conditions.&lt;/P&gt;
&lt;P&gt;It should be noted that WSK is not the source of the vulnerability and no change to WSK is being made in this update.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;How could a malicious user exploit the SMB client&amp;nbsp;vulnerabilities?&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;It is important to understand that both of the vulnerabilities in MS10-006&amp;nbsp;are in the SMB client implementation and do not affect SMB server roles. (For more details regarding SMB client/server roles, see &lt;A href="http://msdn.microsoft.com/en-us/library/aa365233%28VS.85%29.aspx" mce_href="http://msdn.microsoft.com/en-us/library/aa365233(VS.85).aspx"&gt;ref. 2&lt;/A&gt; below) Therefore, in order to exploit this vulnerability, an attacker would have to setup a malicious SMB server and trick the client to connect to it. If your environment does not allow outbound SMB connections to the Internet (best practice), then you are protected from the Internet attack vector. A malicious user on the local network (or a compromised computer) would be able to exploit this issue by performing man-in-the-middle attacks and responding to SMB requests from clients within the Intranet.&lt;/P&gt;
&lt;P&gt;The Internet attack vector would involve browsing to a malicious or compromised website, or receiving HTML email with embedded links to a malicious SMB server. If a victim attempted to retrieve the files or other content specified in the HTML file, an outbound SMB connection&amp;nbsp;would be&amp;nbsp;made and assuming SMB traffic&amp;nbsp;were allowed through the perimeter firewall, the issues could be exploited.&lt;/P&gt;
&lt;P&gt;Depending on your environment, you may not need to place a high priority on the SMB client-side update.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would like to thank Dustin Childs from MSRC and Kowshik Jaganathan and the Windows Sustained Engineering team for their hard work on this update.&lt;/P&gt;
&lt;P&gt;- Bruce Dang and Mark Wodrich, MSRC Engineering&lt;/P&gt;
&lt;P&gt;&lt;B&gt;References:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;1. Winsock Kernel on MSDN (&lt;A href="http://blogs.msdn.com/wndp/archive/2006/02/24/538746.aspx" mce_href="http://blogs.msdn.com/wndp/archive/2006/02/24/538746.aspx"&gt;http://blogs.msdn.com/wndp/archive/2006/02/24/538746.aspx&lt;/A&gt;)&lt;BR&gt;2. SMB client/server roles (&lt;A href="http://msdn.microsoft.com/en-us/library/aa365233%28VS.85%29.aspx" mce_href="http://msdn.microsoft.com/en-us/library/aa365233(VS.85).aspx"&gt;http://msdn.microsoft.com/en-us/library/aa365233(VS.85).aspx&lt;/A&gt;)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3311596" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/SMB/default.aspx">SMB</category><category domain="http://blogs.technet.com/srd/archive/tags/network+protocol/default.aspx">network protocol</category></item><item><title>Details on the New TLS Advisory</title><link>http://blogs.technet.com/srd/archive/2010/02/09/details-on-the-new-tls-advisory.aspx</link><pubDate>Tue, 09 Feb 2010 17:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3311643</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3311643.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3311643</wfw:commentRss><description>&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Security Advisory 977377: Vulnerability in TLS Could Allow Spoofing&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;In August of 2009, researchers at PhoneFactor discovered a vulnerability in the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols. As the issue is present in the actual TLS/SSL-standard, not only our implementation, Microsoft is working together with ICASI, the Industry Consortium for Advancement of Security on the Internet to address this vulnerability. Today, Microsoft released an advisory and an associated workaround package that experienced administrators can use to protect their web services.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Explaining the risk of the security vulnerability&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;The issue, CVE-2009-3555, allows an attacker who successfully became a man-in-the-middle to prepend information to a TLS/SSL protected connection. It does not allow an attacker to read, change or edit the encrypted data. This vulnerability exists because certain SSL-protected protocols, such as HTTP, assume that information received after a TLS-renegotiation is sent by the same client as the information sent before that renegotiation. Renegotiation is a feature of the TLS protocol, described in RFC 2246 which allows either peer to renegotiate the parameters of a protected connection at any point in time. An attacker could exploit this vulnerability by intercepting a legitimate connection from a client, then initiating a renegotiation to the vulnerable server, or by piggybacking on a TLS renegotiation initiated by the web server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;This vulnerability can affect different protocols that use TLS/SSL, but most clearly affected is the HTTPS protocol which protects web transactions.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;IIS 6, IIS 7, IIS 7.5 not affected in default configuration&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Customers using Internet Information Services (IIS) 6, 7 or 7.5 are not affected in their default configuration. These versions of IIS do not support client-initiated renegotiation, and will also not perform a server-initiated renegotiation. If there is no renegotiation, the vulnerability does not exist. The only situation in which these versions of the IIS web server are affected is when the server is configured for certificate-based mutual authentication, which is not a common setting.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Scope of the vulnerability in IIS 5&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;IIS 5 does allow clients to initiate a TLS renegotiation and is vulnerable in its default configuration. Our investigation has shown it is unlikely that these attacks will be exploited successfully. An attacker would already need to successfully leverage a man-in-the-middle attack to intercept a connection between a client and vulnerable server in order to exploit this vulnerability. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Likelihood of the vulnerability being exploited in general case&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Eric Lawrence, a Program Manager in the Internet Explorer security team also evaluated the exploitability of the vulnerability and found the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 0.5in;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;The below is an example of an exploitation of this vulnerability. The text in red is prepended to an SSL connection by an attacker, the text in blue is sent by the unwitting victim client, and the text in green is the web server’s response:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;GET /app/transaction.asp?action=sendMoney&amp;amp;srcAcctID=12345&amp;amp;targetAcctID=6666&amp;amp;amount=2000 HTTP/1.1&lt;br&gt;X-Ignore-This-Line: &lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: blue; font-size: 8pt;"&gt;GET /app/updatecheck.asp HTTP/1.1&lt;br&gt;User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; Trident/4.0;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="background: yellow none repeat scroll 0% 0%; line-height: 115%; font-family: 'Courier New'; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: blue; font-size: 8pt;"&gt;Cookie: PREF=ID=0d3e398a45b12d8a:U=ed647eec50a4edca:HSID=AOHxfGVRaYatVUIUs&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: blue; font-size: 8pt;"&gt;&lt;br&gt;&lt;span style="background: yellow none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;"&gt;Authorization: Basic c2VjcmV0OnBhc3N3b3Jk&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: blue; font-size: 8pt;"&gt;Host: &lt;/span&gt;&lt;a href="http://www.victim.com/" mce_href="http://www.victim.com/"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; font-size: 8pt;"&gt;&lt;font color="#0000ff"&gt;www.victim.com&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: rgb(31, 73, 125); font-size: 8pt;"&gt;&lt;br&gt;&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Times New Roman','serif'; font-size: 12pt;"&gt;&lt;br&gt;&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: green; font-size: 8pt;"&gt;HTTP/1.1 200 OK&lt;br&gt;Content-Type: text/html&lt;br&gt;Server: Microsoft-IIS/6.0&lt;br&gt;Connection: close&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: green; font-size: 8pt;"&gt;&amp;lt;html&amp;gt;&amp;lt;body&amp;gt;Successfully sent $2000USD from account #12345 to account #6666.&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Times New Roman','serif'; font-size: 12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 0.5in;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;&lt;font size="3"&gt;The lines highlighted in yellow represent client state or identification information; by being in the same header block as the attacker’s request, they effectively authorize that spliced request.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 0.5in;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;&lt;font size="3"&gt;There are two reasons why this attack is unlikely to be exploited:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt 1in; text-indent: -0.25in;" class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style=""&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;&lt;font size="3"&gt;If a site is vulnerable to this attack, they are almost certainly vulnerable to classic Cross Site Request Forgery style of attack.&amp;nbsp; The attacker need only send the client some HTML containing an IMG SRC to the victim URL and the client will dereference that URL, automatically providing the credentials to the server.&amp;nbsp; This is a simpler mechanism of accomplishing the same thing than the more complicated TLS/SSL and request-splicing attack hopes to achieve.&lt;br style=""&gt;&lt;br style=""&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in; text-indent: -0.25in;" class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style=""&gt;&lt;font size="3"&gt;·&lt;/font&gt;&lt;span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;span style=""&gt;If&lt;i&gt; &lt;/i&gt;&lt;/span&gt;an attacker were able to overcome the previous issue, this technique will not work for a site that only accepts parameters via HTTP POST requests.&amp;nbsp; The reason is that the attacker must convey the malicious request within the POST’s body.&amp;nbsp; By definition, the HTTP POST body occurs &lt;i&gt;after &lt;/i&gt;the request header block has completed.&amp;nbsp; So, the malicious attack would look something like this:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;POST /app/transaction.asp HTTP/1.1&lt;br&gt;Host: &lt;/span&gt;&lt;a href="http://www.victim.com/" mce_href="http://www.victim.com/"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;www.victim.com&lt;/span&gt;&lt;/a&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;Content-Type: application/x-www-form-urlencoded&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;Content-Length: 62&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;&lt;br&gt;action=sendMoney&amp;amp;srcAcctID=12345&amp;amp;targetAcctID=6666&amp;amp;amount=2000&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: blue; font-size: 8pt;"&gt;GET /app/updatecheck.asp HTTP/1.1&lt;br&gt;User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2;&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: rgb(31, 73, 125); font-size: 8pt;"&gt; &lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: blue; font-size: 8pt;"&gt;Trident/4.0;)&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="background: yellow none repeat scroll 0% 0%; line-height: 115%; font-family: 'Courier New'; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: blue; font-size: 8pt;"&gt;Cookie: PREF=ID=0d3e398a45b12d8a:U=ed647eec50a4edca:HSID=AOHxfGVRaYatVUIUs&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: blue; font-size: 8pt;"&gt;&lt;br&gt;&lt;span style="background: yellow none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;"&gt;Authorization: Basic c2VjcmV0OnBhc3N3b3Jk&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: blue; font-size: 8pt;"&gt;Host: &lt;/span&gt;&lt;a href="http://www.victim.com/" mce_href="http://www.victim.com/"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; font-size: 8pt;"&gt;&lt;font color="#0000ff"&gt;www.victim.com&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: rgb(31, 73, 125); font-size: 8pt;"&gt; &lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; font-size: 8pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: green; font-size: 8pt;"&gt;HTTP/1.1 400 Bad Request&lt;br&gt;Content-Type: text/html&lt;br&gt;Server: Microsoft-IIS/6.0&lt;br&gt;Connection: close&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; font-size: 8pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: green; font-size: 8pt;"&gt;&amp;lt;html&amp;gt;&amp;lt;body&amp;gt;Credentials required.&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Times New Roman','serif'; font-size: 12pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Because the victim’s spliced request is sent &lt;i&gt;after &lt;/i&gt;the header block, the credentials will not be used to authenticate the submitted transaction.&amp;nbsp; The &lt;i&gt;only&lt;/i&gt; way an attacker could make this work is if the server accepted what are called “Trailer” headers from the HTTP request, like so:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1.5in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;POST /app/transaction.asp HTTP/1.1&lt;br&gt;Host: &lt;/span&gt;&lt;a href="http://www.victim.com/" mce_href="http://www.victim.com/"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;www.victim.com&lt;/span&gt;&lt;/a&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1.5in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;Content-Type: application/x-www-form-urlencoded&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1.5in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;Transfer-Encoding: chunked&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1.5in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;Trailer: Authorization, Cookie, X-Ignore&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1.5in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;&lt;br&gt;3E&lt;br&gt;action=sendMoney&amp;amp;srcAcctID=12345&amp;amp;targetAcctID=6666&amp;amp;amount=2000&lt;br&gt;0&lt;br&gt;X-Ignore: &lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: blue; font-size: 8pt;"&gt;GET /app/updatecheck.asp HTTP/1.1&lt;br&gt;User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; Trident/4.0;)&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: red; font-size: 8pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1.5in;" class="MsoNormal"&gt;&lt;span style="background: yellow none repeat scroll 0% 0%; line-height: 115%; font-family: 'Courier New'; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: blue; font-size: 8pt;"&gt;Cookie: PREF=ID=0d3e398a45b12d8a:U=ed647eec50a4edca:HSID=AOHxfGVRaYatVUIUs&lt;/span&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: blue; font-size: 8pt;"&gt;&lt;br&gt;&lt;span style="background: yellow none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;"&gt;Authorization: Basic c2VjcmV0OnBhc3N3b3Jk&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1.5in;" class="MsoNormal"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; color: blue; font-size: 8pt;"&gt;Host: &lt;/span&gt;&lt;a href="http://www.victim.com/" mce_href="http://www.victim.com/"&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; font-size: 8pt;"&gt;&lt;font color="#0000ff"&gt;www.victim.com&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="line-height: 115%; font-family: 'Courier New'; font-size: 8pt;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;However, it is unlikely that real-life web applications actually would accept this type of Trailer header, as it is a very little-used part of HTTP, not supported by mainstream browsers such as Internet Explorer.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;b style=""&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Workaround package available to disable TLS renegotiation&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;While a comprehensive, multi-vendor fix is in the works, today we released a workaround package which allows system administrators to disable TLS renegotiation on their server. This package is described in KB article 977377 and disables TLS/SSL renegotiation for all TLS/SSL-protected protocols. We need to stress that TLS/SSL renegotiation is a feature of the protocol that is used by several applications. One common example is Microsoft Exchange and ActiveSync. These applications may operate inappropriately upon installation of this workaround package. &lt;span style=""&gt;&amp;nbsp;&lt;/span&gt;We recommend that administrators carefully test the workaround prior to deploying it on production systems. The package will protect all clients making SSL connections to the server on which it is installed. Installing it on clients will not provide any security benefit.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;We recommend that customers only install this workaround if they have very specific concerns regarding this vulnerability and require an ad-interim solution while Microsoft and other vendors work on a revision of the protocol.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Despite the low risk of active exploitation, this vulnerability breaches a security promise made by the TLS protocol and we intend to address it comprehensively. We are working with the relevant standards body and our partners in ICASI to ensure that our fix for this issue is compatible with third party SSL/TLS-enabled solutions. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Thanks to Nasko Oskov from Windows Security, Eric Lawrence from Internet Explorer and Jonathan Ness from the MSRC Engineering team for their significant contributions to this blog post.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;-Maarten Van Horenbeeck, MSRC Program Manager&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;*Posting is provided "AS IS" with no warranties, and confers no rights.*&lt;/p&gt;&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3311643" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/Mitigations/default.aspx">Mitigations</category><category domain="http://blogs.technet.com/srd/archive/tags/Workarounds/default.aspx">Workarounds</category><category domain="http://blogs.technet.com/srd/archive/tags/network+protocol/default.aspx">network protocol</category><category domain="http://blogs.technet.com/srd/archive/tags/Risk+Asessment/default.aspx">Risk Asessment</category><category domain="http://blogs.technet.com/srd/archive/tags/IIS/default.aspx">IIS</category></item><item><title>Reports of DEP being bypassed</title><link>http://blogs.technet.com/srd/archive/2010/01/20/reports-of-dep-being-bypassed.aspx</link><pubDate>Wed, 20 Jan 2010 18:01:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3307093</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3307093.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3307093</wfw:commentRss><description>&lt;P&gt;Yesterday we heard reports of a commercially available exploit that bypasses DEP. This exploit was made available to a limited number of major security vendors (Antivirus, IDS, and IPS vendors) and government CERT agencies. We wanted to use this opportunity to give an overview of current customer risk related to this DEP bypass.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Real-world attacks so far still only effective against Internet Explorer 6&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;We have seen an increase in attacks attempting to exploit the vulnerability detailed in &lt;A href="http://www.microsoft.com/technet/security/advisory/979352.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/979352.mspx"&gt;Security Advisory 979352&lt;/A&gt;. However, all attacks we have seen so far still target Internet Explorer 6 - this is also confirmed by the attack samples our Microsoft Active Protections Program (MAPP) &lt;A href="http://www.microsoft.com/security/msrc/collaboration/mapppartners.aspx" mce_href="http://www.microsoft.com/security/msrc/collaboration/mapppartners.aspx"&gt;partners&lt;/A&gt; have sent in.&lt;/P&gt;
&lt;P&gt;While we have not seen real-world attacks for any other platform, we have seen researchers poking at other platforms and have seen the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Private proof-of-concept code exploiting IE7 on Windows XP for arbitrary code execution&lt;/LI&gt;
&lt;LI&gt;Private proof-of-concept code exploiting IE7 on Windows Vista without DEP enabled for code execution within the Protected Mode sandbox. We are not aware of any proof-of-concept code exploiting Windows Vista with DEP enabled.&lt;/LI&gt;
&lt;LI&gt;Commercial, limited distribution proof-of-concept code exploiting IE8 on Windows XP with DEP enabled for arbitrary code execution. &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;B&gt;State-of-the-art of attacker research on various platforms&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Here’s the current state-of-the-art on each platform:&lt;/P&gt;
&lt;TABLE border=1&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Windows XP&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Windows Vista&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Windows 7&lt;/B&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;B&gt;IE 6&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;Public exploit code consistently reliable for arbitrary code execution&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;B&gt;IE 7&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;Private proof-of-concept is likely consistently reliable for arbitrary code execution&lt;/TD&gt;
&lt;TD&gt;Private proof-of-concept is likely consistently reliable for limited code execution within the Protected Mode sandbox. &lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;B&gt;IE 8&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;In our testing, the commercially-available, limited distribution exploit does result in successful code execution with DEP enabled.&lt;/TD&gt;
&lt;TD&gt;No known proof-of-concept code. Current exploits modified for use on Windows Vista would likely be effective for limited code execution within the Protected Mode sandbox on 1% of exploit attempts. It would result in an Internet Explorer crash for 99% of exploit attempts. Exploits are substantially less reliable due to the presence of ASLR on Windows Vista.&lt;/TD&gt;
&lt;TD&gt;No known proof-of-concept code. Current exploits modified for use on&amp;nbsp;Windows 7 would likely be effectively for limited code execution within the Protected Mode sandbox on 1% of exploit attempts. It would result in an Internet Explorer crash for 99% of exploit attempts. Exploits are substantially less reliable due to the presence of ASLR on Windows 7.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;B&gt;Other mitigations (besides DEP)&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;We have discussed DEP at length in this blog. As you can see in the table above, two other mitigations help prevent or limit the impact of attacks on later platforms. &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;B&gt;Internet Explorer Protected Mode&lt;/B&gt; limits the impact of Windows Vista and Windows 7 exploits. Attackers who are able to successfully exploit Internet Explorer on those platforms are stuck in a “sandbox”, potentially able to read data but unable to install programs or change system configuration.&lt;/LI&gt;
&lt;LI&gt;&lt;B&gt;Address Space Layout Randomization (ASLR)&lt;/B&gt; makes exploiting vulnerabilities more difficult by relocating normally-predictable code locations pseudo-randomly in memory. ASLR re-bases DLL’s to random locations in memory, making ret2libc type attacks unreliable. Due to ASLR we believe exploits for Internet Explorer 8 on Windows Vista or Windows 7 could result in limited code execution for 1% of attempts.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;B&gt;Out-of-band update coming tomorrow&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;We’ll be releasing a comprehensive, well-tested security update tomorrow morning PST&amp;nbsp;to address this vulnerability. In the meantime, we hope this information helps you assess risk and protect your environment. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;Acknowledgements&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Thanks Matt Miller and John Lambert for help with the ASLR arithmetic and other feedback.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Update Jan 20, 2010:&amp;nbsp; Updated "less than 1%" to "1%".&amp;nbsp; Thanks reader Larry&amp;nbsp;for catching arithmetic error.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Update Jan 22, 2010:&amp;nbsp; Updated to reflect new understanding of the commercially-available, limited distribution exploit on IE8 / XP SP3.&amp;nbsp; Also removed formula behind the theoretical 1% ASLR success chance.&amp;nbsp; The formula was off by a fraction of a percentage point and the math to describe it would be difficult to explain.&amp;nbsp; The chance is approximately 1.1%.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- Jonathan Ness, MSRC Engineering&lt;/P&gt;
&lt;P&gt;*Posting is provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3307093" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/Mitigations/default.aspx">Mitigations</category><category domain="http://blogs.technet.com/srd/archive/tags/exploitation/default.aspx">exploitation</category><category domain="http://blogs.technet.com/srd/archive/tags/Internet+Explorer+_2800_IE_2900_/default.aspx">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/srd/archive/tags/Exploitability/default.aspx">Exploitability</category><category domain="http://blogs.technet.com/srd/archive/tags/Risk+Asessment/default.aspx">Risk Asessment</category><category domain="http://blogs.technet.com/srd/archive/tags/MSHTML/default.aspx">MSHTML</category><category domain="http://blogs.technet.com/srd/archive/tags/DEP/default.aspx">DEP</category></item><item><title>Additional information about DEP and the Internet Explorer 0day vulnerability</title><link>http://blogs.technet.com/srd/archive/2010/01/18/additional-information-about-dep-and-the-internet-explorer-0day-vulnerability.aspx</link><pubDate>Tue, 19 Jan 2010 02:13:43 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3306551</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3306551.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3306551</wfw:commentRss><description>&lt;p&gt;The new Internet Explorer security vulnerability described by Microsoft &lt;a href="http://www.microsoft.com/technet/security/advisory/979352.mspx" target="_blank"&gt;Security Advisory 979352&lt;/a&gt; has received a lot of interest over the past few days. The Internet Explorer team is hard at work preparing a comprehensive security update to address the vulnerability and the &lt;a href="http://blogs.technet.com/msrc"&gt;MSRC&lt;/a&gt; announced today that as soon as the update is ready for broad distribution, it will be released.&lt;/p&gt;  &lt;p&gt;We have heard several questions from customers attempting to protect their environment in the meantime. Most questions have been around Data Execution Prevention (DEP), a mitigation we discussed in our &lt;a href="http://blogs.technet.com/srd/archive/2010/01/15/assessing-risk-of-ie-0day-vulnerability.aspx"&gt;previous blog post&lt;/a&gt;. To help you better understand DEP specifically as it relates to Internet Explorer 8, we have prepared the following video where I discuss some of the higher level concepts:&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="540"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="250"&gt;&lt;object data="data:application/x-silverlight-2," type="application/x-silverlight-2" width="320" height="240"&gt; &lt;param name="source" value="http://edge.technet.com/App_Themes/default/vp09_06_22.xap" /&gt; &lt;param name="initParams" value="m=http://ecn.channel9.msdn.com/o9/edge/4/8/3/5/1/msrcdepjon118_edge.wmv,autostart=false,autohide=true,showembed=true, thumbnail=http://ecn.channel9.msdn.com/o9/edge/4/8/3/5/1/msrcdepjon118_320_edge.png, postid=15384" /&gt; &lt;param name="background" value="#00FFFFFF" /&gt; &lt;a href="http://go.microsoft.com/fwlink/?LinkID=124807" style="text-decoration: none;"&gt; &lt;img src="http://go.microsoft.com/fwlink/?LinkId=108181" alt="Get Microsoft Silverlight" style="border-style: none" /&gt; &lt;/a&gt; &lt;/object&gt;&lt;/td&gt;        &lt;td valign="top" width="288"&gt;More listening and viewing options:          &lt;br /&gt;          &lt;ul&gt;           &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/4/8/3/5/1/msrcdepjon118_edge.wmv"&gt;Windows Media Video (WMV)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/4/8/3/5/1/msrcdepjon118_edge.wma"&gt;Windows Media Audio (WMA)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/4/8/3/5/1/msrcdepjon118_edge.mp4"&gt;iPod Video (MP4)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/4/8/3/5/1/msrcdepjon118_edge.mp3"&gt;MP3 Audio&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/4/8/3/5/1/msrcdepjon118_2MB_edge.wmv"&gt;High Quality WMV (2.5 Mbps)&lt;/a&gt; &lt;/li&gt;            &lt;li&gt;&lt;a href="http://ecn.channel9.msdn.com/o9/edge/4/8/3/5/1/msrcdepjon118_Zune_edge.wmv"&gt;Zune Video (WMV)&lt;/a&gt; &lt;/li&gt;         &lt;/ul&gt;       &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;To summarize:&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Which versions of Internet Explorer have enabled DEP by default?&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Hardware-enforced DEP is enabled by default for Internet Explorer on the following platforms:&lt;/p&gt;  &lt;p&gt;· Internet Explorer 8 on Windows XP Service Pack 3,&lt;/p&gt;  &lt;p&gt;· Internet Explorer 8 on Windows Vista Service Pack 1 and later,&lt;/p&gt;  &lt;p&gt;· Internet Explorer 8 on Windows Server 2008, and &lt;/p&gt;  &lt;p&gt;· Internet Explorer 8 on Windows 7.&lt;/p&gt;  &lt;p&gt;Windows 2000 has no support for hardware-enforced DEP. Windows XP Service Pack 2, Windows Server 2003 Service Pack 1, and Windows Vista support hardware-enforced DEP do not have the SetProcessDEPPolicy API that Internet Explorer 8 uses to enable DEP.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;How can users of other versions of Windows or Internet Explorer enable DEP?&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Windows XP SP2 and Windows Vista RTM users can click this button to launch an MSI that will enable DEP for Internet Explorer.&lt;/p&gt;  &lt;p&gt;&lt;/p&gt; &lt;center&gt;&lt;a href="http://go.microsoft.com/?linkid=9668626" mce_href="http://go.microsoft.com/?linkid=9668626"&gt;&lt;img src="http://blogs.technet.com/photos/swiblog/images/3306047/original.aspx" mce_src="http://blogs.technet.com/photos/swiblog/images/3306047/original.aspx" /&gt;&lt;/a&gt;&lt;/center&gt;  &lt;p&gt;&lt;b&gt;How can you determine whether hardware-enforced DEP is available with your hardware?&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Microsoft &lt;a href="http://support.microsoft.com/kb/912923" target="_blank"&gt;KB 912923&lt;/a&gt; describes in more detail how to determine that hardware DEP is available and configured on your computer.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;What is the difference between &amp;quot;Software DEP&amp;quot; and hardware-enforced DEP (/NX)?&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&amp;quot;Software DEP&amp;quot; is unfortunately really not DEP at all. &amp;quot;Software DEP&amp;quot; is just another name for /SAFESEH [MSDN link]. Unfortunately, /SAFESEH is not an effective mitigation for this vulnerability. Only hardware-enforced DEP disrupts exploits attempting to abuse this vulnerability.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Does IE’s DEP behave differently in the Intranet Zone (as compared to the Internet Zone)?&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;DEP itself is enabled per process, regardless of application-layer content. However, a well-known DEP bypass is used by attackers to mark pages executable using .NET classes. IE8 does not allow these .NET class to load in the Internet Zone. In the Intranet Zone, the .NET classes are allowed to load. Therefore, an attacker capable of hosting content on your corporate network may be able to bypass DEP and successfully exploit this vulnerability.&lt;/p&gt;  &lt;p&gt;We hope that helps answer questions you may have had about DEP. &lt;/p&gt;  &lt;p&gt;Jonathan Ness&lt;/p&gt;  &lt;p&gt;*This posting is provided &amp;quot;AS IS&amp;quot; with no warranties, and confers no rights*&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3306551" width="1" height="1"&gt;</description></item><item><title>Assessing risk of IE 0day vulnerability</title><link>http://blogs.technet.com/srd/archive/2010/01/15/assessing-risk-of-ie-0day-vulnerability.aspx</link><pubDate>Sat, 16 Jan 2010 00:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3306043</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3306043.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3306043</wfw:commentRss><description>&lt;P&gt;Yesterday, the MSRC released &lt;A href="http://www.microsoft.com/technet/security/advisory/979352.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/979352.mspx"&gt;Microsoft Security Advisory 979352&lt;/A&gt; alerting customers to limited, sophisticated&amp;nbsp;attacks targeting Internet Explorer 6 customers. Today, samples of that exploit were made publicly available.&lt;/P&gt;
&lt;P&gt;Before we get into the details I want to make one thing perfectly clear. The attacks we have seen to date, including the exploit released publicly, only affect customers using Internet Explorer 6. As discussed in the security advisory, while newer versions of Internet Explorer are affected by this vulnerability, mitigations exist that make exploitation much more difficult. We would like to share a little more information about both the vulnerability and the exploits we have seen to help you understand the risk to your organization. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;Risk, by platform&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Newer versions of Internet Explorer and later Windows releases are at reduced risk to the exploit we have seen due to platform mitigations explained in the blog post below. (Note:&amp;nbsp;Server platforms are omitted from this table&amp;nbsp;because browsing is less likely from Servers.)&lt;/P&gt;
&lt;TABLE border=1&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Windows 2000&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Windows XP&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Windows Vista&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Windows 7&lt;/B&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;B&gt;Internet Explorer 6&lt;/B&gt;&lt;/TD&gt;
&lt;TD bgColor=red&gt;Exploitable&lt;/TD&gt;
&lt;TD bgColor=red&gt;Exploitable (current exploit effective for code execution)&lt;/TD&gt;
&lt;TD&gt;N/A&lt;BR&gt;(Vista ships with IE7)&lt;/TD&gt;
&lt;TD&gt;N/A&lt;BR&gt;(Windows 7 ships with IE 8)&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;B&gt;Internet Explorer 7&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;N/A&lt;BR&gt;(IE 7 will not install on Windows 2000)&lt;/TD&gt;
&lt;TD bgColor=yellow&gt;Potentially exploitable (current exploit does not currently work due to memory layout differences in IE 7)&lt;/TD&gt;
&lt;TD bgColor=green&gt;IE Protected Mode prevents current exploit from working.&lt;/TD&gt;
&lt;TD&gt;N/A&lt;BR&gt;(Windows 7 ships with IE 8)&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;B&gt;Internet Explorer 8&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;N/A&lt;BR&gt;(IE 8 will not install on Windows 2000)&lt;/TD&gt;
&lt;TD bgColor=green&gt;DEP enabled by default on XP SP3 prevents exploit from working.&lt;/TD&gt;
&lt;TD bgColor=green&gt;IE Protected Mode + DEP enabled by default prevent exploit from working.&lt;/TD&gt;
&lt;TD bgColor=green&gt;IE Protected Mode + DEP enabled by default prevent exploit from working.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;As you can see, the client configuration currently at risk is Windows XP running IE6. We recommend users of IE6 on Windows XP upgrade to a new version of Internet Explorer and/or enable DEP. Users of other platforms are at reduced risk.&amp;nbsp; We also recommend users of Windows XP upgrade to newer versions of Windows.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;More information about the vulnerability&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The vulnerability is an Internet Explorer memory corruption issue triggered by an attacker using JavaScript to copy, release, and then later reference a specific Document Object Model (DOM) element. If an attacker is able to prepare&amp;nbsp;memory with attack code,&amp;nbsp;the reference to a random location of freed memory could result in execution of the attacker’s code.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Ways to block Code Execution&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The vulnerability is present in Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8. All versions may crash after opening the attack code. However, there are a number of ways to limit the attack to an IE crash and prevent attacker code execution.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Disable JavaScript. &lt;A href="http://www.microsoft.com/technet/security/advisory/979352.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/979352.mspx"&gt;Microsoft Security Advisory 979352&lt;/A&gt; includes this workaround but we understand that this workaround significantly impacts usability of many Web sites.&lt;BR&gt;&lt;BR&gt;&lt;/LI&gt;
&lt;LI&gt;Disable code executing from random locations of freed memory. Data Execution Prevention (DEP) prevents the execution of code from pages of memory that are not explicitly marked as executable. DEP is a supported feature on Windows XP Service Pack 2 and higher, Windows Server 2003 Service Pack 2 and higher, and all versions of Windows Vista, Windows Server 2008,&amp;nbsp;and Windows 7. Some platforms enable DEP by default (see below). You can read more about DEP in this blog &lt;A href="http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-1.aspx" mce_href="http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-1.aspx"&gt;here&lt;/A&gt; and &lt;A href="http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx" mce_href="http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx"&gt;here&lt;/A&gt;. You can enable DEP on Windows XP and Windows Vista by clicking the Microsoft Fix It&amp;nbsp;button below. (DEP is enabled by default for Internet Explorer 8 running on XP Service Pack 3, Windows Vista Service Pack 1 and higher, and Windows 7, so you do not need to use the "Microsoft Fix It" for those configurations.)&lt;/LI&gt;&lt;/UL&gt;
&lt;CENTER&gt;&lt;A href="http://go.microsoft.com/?linkid=9668626" mce_href="http://go.microsoft.com/?linkid=9668626"&gt;&lt;IMG src="http://blogs.technet.com/photos/swiblog/images/3306047/original.aspx" mce_src="http://blogs.technet.com/photos/swiblog/images/3306047/original.aspx"&gt;&lt;/A&gt;&lt;/CENTER&gt;
&lt;P&gt;&lt;B&gt;Note on enabling DEP for Windows Vista&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The security advisory lists steps to enable DEP for Internet Explorer 7. To enable DEP on Windows Vista, be sure to run Internet Explorer as an Administrator (Right-click, and then select “Run as Administrator”). After enabling DEP, close the Internet Explorer session and re-launch Internet Explorer to browse with DEP enabled. The option will be grayed-out if you are not running Internet Explorer as an Administrator.&lt;/P&gt;
&lt;P&gt;If you enable DEP on Windows Vista using the Microsoft Fix It, you will not see the Internet Explorer user interface change.&amp;nbsp; However, after restarting Internet Explorer, you can use a&amp;nbsp;tool like &lt;A href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" mce_href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx"&gt;Process Explorer&lt;/A&gt; to verify that DEP is enabled.&amp;nbsp; The Internet Explorer user interface displays value of a registry key while the Microsoft Fix It enables&amp;nbsp;DEP by using an appcompat shim.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Acknowledgements&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Big thanks to Chengyun Chu for his exploit analysis and risk assessment help. And thanks to Rob Hensing for the DEP research and FixIt4Me MSI help. Thanks to Fermin J. Serna for the vulnerability analysis. Lots of people at Microsoft are working on this, thanks everybody.&lt;/P&gt;
&lt;P&gt;- Jonathan Ness, MSRC Engineering&lt;/P&gt;
&lt;P&gt;*Posting is provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3306043" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/Mitigations/default.aspx">Mitigations</category><category domain="http://blogs.technet.com/srd/archive/tags/Attack/default.aspx">Attack</category><category domain="http://blogs.technet.com/srd/archive/tags/Exploitability/default.aspx">Exploitability</category><category domain="http://blogs.technet.com/srd/archive/tags/Risk+Asessment/default.aspx">Risk Asessment</category><category domain="http://blogs.technet.com/srd/archive/tags/MSHTML/default.aspx">MSHTML</category><category domain="http://blogs.technet.com/srd/archive/tags/DEP/default.aspx">DEP</category><category domain="http://blogs.technet.com/srd/archive/tags/Zero-Day+Exploit/default.aspx">Zero-Day Exploit</category></item><item><title>MS10-001: Font file decompression vulnerability</title><link>http://blogs.technet.com/srd/archive/2010/01/12/ms10-001-font-file-decompression-vulnerability.aspx</link><pubDate>Tue, 12 Jan 2010 18:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3304619</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3304619.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3304619</wfw:commentRss><description>&lt;P&gt;&lt;A href="http://www.microsoft.com/technet/security/bulletin/MS10-001.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS10-001.mspx"&gt;MS10-001&lt;/A&gt; addresses a vulnerability (CVE-2010-0018 ) in the LZCOMP de-compressor for Microtype Express Fonts. This blog aims to answer some questions regarding the updates we’ve made in this area.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;What is the issue?&lt;/B&gt;&lt;BR&gt;t2embed.dll improperly performs bounds-checking on lengths which are decoded from the LZCOMP bit-stream. This made it possible for a copy loop to violate the intended working buffer.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Is the EOT functionality reachable through 3rd party code?&lt;BR&gt;&lt;/STRONG&gt;Yes, the t2embed library provides EOT functionality that can be used by 3rd party code.&amp;nbsp;&amp;nbsp;Many 3rd parties import&amp;nbsp;t2embed for their font rendering, though some may choose to implement their own font rendering.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Why an Exploitability Index rating of 2?&lt;/B&gt;&lt;BR&gt;The Exploitability Index rating or 2 is due to the low likelihood of successful exploitation. Hurdles exist around heap preparation and predictability, heap data corruption, and a race condition to get an exception handler making successful exploitation unlikely. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;What is the likelihood of successful exploitation?&lt;/B&gt;&lt;BR&gt;Due to the nature of bounds-checking performed in t2embed on 32-bit systems XP and later, the only buffer+index combinations which would pass the old checks will point into address 0x80000000 and above.&amp;nbsp;Because these regions cannot be accessed while running at IOPL 3, the process will crash (Access Violate) and the attempt to run arbitrary code would fail. &lt;/P&gt;
&lt;P&gt;On Windows 2000, this vulnerability could be abused to leverage code execution. On 32-bit platforms post Windows 2000, improper memory access would commonly be observed in the form of a Read Access Violation at address 0x80000000&amp;nbsp;or above, though the memory layout on /3GB-enabled systems could be manipulated to compromise the integrity of the hosting process. Stability (Denial of Service) implications exist on these systems when /3GB is not enabled (default), whereas /3GB-enabled systems run a risk of code execution, though no known attack vectors exist in Microsoft products. &lt;/P&gt;
&lt;P&gt;Third party products which are (A) large address aware (&lt;A href="http://msdn.microsoft.com/en-us/library/wz223b1z(VS.80).aspx" mce_href="http://msdn.microsoft.com/en-us/library/wz223b1z(VS.80).aspx"&gt;http://msdn.microsoft.com/en-us/library/wz223b1z(VS.80).aspx&lt;/A&gt;), (B) consume the t2embed, and are (C) running on a /3GB-enabled system should be considered exploitable. &lt;/P&gt;
&lt;P&gt;On 64-bit platforms, improper memory access would commonly be observed in the form of a Read Access Violation at a kernel mode address which would affect application stability (Denial of Service) with no threat of code-execution. &lt;/P&gt;
&lt;P&gt;Here is a table to represent the exploitation scenarios described above: &lt;/P&gt;
&lt;TABLE border=1&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;/2GB &lt;U&gt;not&lt;/U&gt; running Large Address Aware Application&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;/3GB &lt;U&gt;not&lt;/U&gt; running Large Address Aware Application&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;/2GB running Large Address Aware Application&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;/3GB running Large Address Aware Application&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;32-bit XP and newer &lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Denial of Service&lt;/TD&gt;
&lt;TD&gt;Denial of Service&lt;/TD&gt;
&lt;TD&gt;Denial of Service&lt;/TD&gt;
&lt;TD&gt;Chance for Code Execution&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;64-bit XP and newer &lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Denial of Service&lt;/TD&gt;
&lt;TD&gt;Denial of Service&lt;/TD&gt;
&lt;TD&gt;Denial of Service&lt;/TD&gt;
&lt;TD&gt;Denial of Service&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Windows 2000&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;Chance for Code Execution&lt;/TD&gt;
&lt;TD&gt;Chance for Code Execution&lt;/TD&gt;
&lt;TD&gt;Chance for Code Execution&lt;/TD&gt;
&lt;TD&gt;Chance for Code Execution&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/B&gt;
&lt;P&gt;The Windows 2000 severity rating of critical was chosen due to the vulnerable code being exposed through client applications that can render EOT fonts in a way that does not require user interaction/notification. (such as Microsoft Internet Explorer, Microsoft Office PowerPoint, and Microsoft Office Word)&lt;/P&gt;
&lt;P&gt;&lt;B&gt;What are the attack vectors?&lt;/B&gt;&lt;BR&gt;Remote attack vectors&amp;nbsp;are all in user-mode:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Malicious fonts (EOT) delivered within files hosted on malicious web sites which are rendered in all versions of Internet Explorer by default.&lt;/LI&gt;
&lt;LI&gt;Malicious office documents e-mailed to victims with social engineering to entice the victim to open the document which contains a malformed embedded font which would then be rendered upon opening the Office document (PowerPoint and Word documents are the most likely attack vectors).&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;B&gt;How do I protect myself?&lt;/B&gt;&lt;BR&gt;The best option for protecting against this vulnerability is to apply the update for MS10-001.&lt;/P&gt;
&lt;P&gt;As stated in a &lt;A href="http://blogs.technet.com/srd/archive/2009/11/10/font-directory-entry-parsing-vulnerability-in-win32k-sys.aspx" mce_href="http://blogs.technet.com/srd/archive/2009/11/10/font-directory-entry-parsing-vulnerability-in-win32k-sys.aspx"&gt;previous SRD blog post&lt;/A&gt;, another option is to disable support for parsing/loading embedded fonts in IE. The side effect of this approach is that it will cause web sites which make use of embedded font technology to fail to render properly. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;What is /3GB and how can I tell if /3GB is enabled on my system?&lt;/B&gt;&lt;BR&gt;/3GB is a switch and it allows 32-bit systems to benefit from 3GB of addressable memory versus the default 2GB of memory. More information on /3GB can be found &lt;A href="http://msdn.microsoft.com/en-us/library/ms791558.aspx" mce_href="http://msdn.microsoft.com/en-us/library/ms791558.aspx"&gt;here&lt;/A&gt;. You can check to see whether you have /3GB enabled on your system by typing the following command in a shell:&lt;/P&gt;&lt;PRE&gt;C:\&amp;gt;bcdedit.exe /v

Windows Boot Manager
--------------------
identifier              {9dea862c-5cdd-4e70-acc1-f32b344d4795}
device                  partition=D:
description             Windows Boot Manager
locale                  en-US
inherit                 {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
default                 {4a81cc63-2e99-11de-a190-00188b749f31}
resumeobject            {4a81cc62-2e99-11de-a190-00188b749f31}
displayorder            {4a81cc63-2e99-11de-a190-00188b749f31}
toolsdisplayorder       {b2721d73-1db4-4c62-bf78-c548a880142d}
timeout                 30

Windows Boot Loader
-------------------
identifier              {4a81cc63-2e99-11de-a190-00188b749f31}
device                  partition=C:
path                    \Windows\system32\winload.exe
description             Microsoft Windows Vista
locale                  en-US
inherit                 {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
bootdebug               Yes
osdevice                partition=C:
systemroot              \Windows
resumeobject            {4a81cc62-2e99-11de-a190-00188b749f31}
nx                      OptIn
increaseuserva          3072
debug                   No
&lt;/PRE&gt;
&lt;P&gt;Note the increaseuserva variable. If unset (or set to 2048), you do not have /3GB enabled. If this value is set to 3072 (as seen here) you have /3GB enabled.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;What is LZCOMP?&lt;/B&gt;&lt;BR&gt;LZCOMP is a compression algorithm variation of the LZ77 theme. A great explanation of LZCOMP and how it differs from LZ77 can be found &lt;A href="http://www.w3.org/Submission/MTX/#Theory" mce_href="http://www.w3.org/Submission/MTX/#Theory"&gt;here&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;Where does the LZCOMP de-compressor component reside on my system?&lt;/B&gt;&lt;BR&gt;The LZCOMP de-compressor exists within the t2embed dynamically linked library. It commonly resides in %SystemRoot%\System32 and is imported by programs such as Office and Internet Explorer. &lt;/P&gt;
&lt;P&gt;&lt;B&gt;How does this Fonts vulnerability differ from the previous Fonts vulnerability addressed by MS09-065?&lt;/B&gt;&lt;BR&gt;This vulnerability exists in a user-mode component (t2embed.dll) whereas the previous Fonts vulnerability (&lt;A href="http://www.microsoft.com/technet/security/bulletin/MS09-065.mspx" mce_href="http://www.microsoft.com/technet/security/bulletin/MS09-065.mspx"&gt;MS09-065&lt;/A&gt;) addressed a kernel-mode component (win32k.sys).&lt;/P&gt;
&lt;P&gt;I’d like to thank Matt Miller for general guidance, Bruce Dang and Robert Hensing from the MSRC Engineering Team for their efforts on this release. &lt;/P&gt;
&lt;P&gt;-Brian Cavenah, MSRC Engineering&lt;/P&gt;
&lt;P&gt;*Posting is provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3304619" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/Mitigations/default.aspx">Mitigations</category><category domain="http://blogs.technet.com/srd/archive/tags/Workarounds/default.aspx">Workarounds</category><category domain="http://blogs.technet.com/srd/archive/tags/rating/default.aspx">rating</category><category domain="http://blogs.technet.com/srd/archive/tags/Exploitability/default.aspx">Exploitability</category><category domain="http://blogs.technet.com/srd/archive/tags/Risk+Asessment/default.aspx">Risk Asessment</category><category domain="http://blogs.technet.com/srd/archive/tags/Font/default.aspx">Font</category></item><item><title>Assessing the risk of the December security bulletins</title><link>http://blogs.technet.com/srd/archive/2009/12/08/assessing-the-risk-of-the-december-security-bulletins.aspx</link><pubDate>Tue, 08 Dec 2009 18:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3299184</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3299184.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3299184</wfw:commentRss><description>&lt;P&gt;This morning we released six security bulletins, three Critical and three Important, addressing 12 CVE’s. &lt;B&gt;&lt;U&gt;Please apply the Internet Explorer update right away as it poses the most risk of all the bulletins due to severity and exploitability.&lt;/B&gt;&lt;/U&gt;The Internet Explorer update addresses the vulnerability described by &lt;A href="http://www.microsoft.com/technet/security/advisory/977981.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/977981.mspx"&gt;Security Advisory 977981&lt;/A&gt;. We hope that the table and commentary below will help you prioritize the deployment of the other updates appropriately.&lt;/P&gt;
&lt;TABLE border=1&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;B&gt;Bulletin&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Most likely attack vector&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Bulletin severity&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Max Exploit- ability Index&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Likely first 30 days impact&lt;/B&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;B&gt;Platform mitigations&lt;/B&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;MS09-072 (IE)&lt;/TD&gt;
&lt;TD&gt;Attacker hosts a malicious webpage, lures victim to it.&lt;/TD&gt;
&lt;TD&gt;Critical&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;Public exploit code already exists for CVE-2009-3672 affecting IE6 and IE7. We expect to see exploits for other vulnerabilities that affect other IE versions within 30 days.&lt;/TD&gt;
&lt;TD&gt;DEP is enabled by default for IE8 on Windows XP SP3, Windows Vista SP1 and later, Windows Server 2008, and Windows 7.&lt;BR&gt;&lt;BR&gt;DEP makes exploiting the public vulnerability significantly more difficult.&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;MS09-073 (Wordpad converter)&lt;/TD&gt;
&lt;TD&gt;Attacker sends malicious .doc file (saved in legacy Word version 8 format) to victim who opens it in Wordpad.&lt;/TD&gt;
&lt;TD&gt;Critical&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;Less likely to be exploited in first 30 days.&lt;/TD&gt;
&lt;TD&gt;Affects only older platforms.&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;MS09-071 (IAS)&lt;/TD&gt;
&lt;TD&gt;Attacker on a wireless LAN attacks the Microsoft IAS server providing the 802.1x authentication and encryption via PEAP. Attack would be via the RADIUS protocol.&lt;/TD&gt;
&lt;TD&gt;Critical&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;Less likely to be exploited in first 30 days.&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;MS09-074 (Project)&lt;/TD&gt;
&lt;TD&gt;Attacker sends a malicious Project file (MPP) to victim who opens it with Project 2003 or earlier.&lt;/TD&gt;
&lt;TD&gt;Critical (Critical on Project 2000 only)&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;TD&gt;Less likely to be exploited in first 30 days.&lt;/TD&gt;
&lt;TD&gt;Affects only older versions of Project.&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;MS09-070 (ADFS)&lt;/TD&gt;
&lt;TD&gt;Attacker able to authenticate to ADFS running in IIS can execute code within the IIS worker process.&lt;/TD&gt;
&lt;TD&gt;Important&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;While an exploit may be developed in the first 30 days, the risk to most organizations is low because attack surface is only exposed to authenticated attackers.&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;MS09-069 (LSASS)&lt;/TD&gt;
&lt;TD&gt;Attacker on enterprise network authenticates to a server and remotely causes CPU exhaustion.&lt;/TD&gt;
&lt;TD&gt;Important&lt;/TD&gt;
&lt;TD&gt;3&lt;/TD&gt;
&lt;TD&gt;Unlikely to be exploited in first 30 days.&lt;/TD&gt;
&lt;TD&gt;No chance of code execution&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;This month, we’ve also released an advisory and non-security updates changing Windows behavior around credential forwarding. Maarten Van Horenbeeck explains the current protections against credential reflection and credential forwarding in a blog post at &lt;A href="http://blogs.technet.com/srd/archive/2009/12/08/extended-protection-for-authentication.aspx"&gt;http://blogs.technet.com/srd/archive/2009/12/08/extended-protection-for-authentication.aspx&lt;/A&gt;. Definitely take a look if you are concerned about safeguarding credentials against these types of attacks.&lt;/P&gt;
&lt;P&gt;Also, we have also released an advisory describing a security mitigation offered to all customers through Windows Update. The Indeo Codec is an older codec that is known to have several security vulnerabilities. Instead of fixing one-off vulnerabilities in this older codec, we’ve released an update that blocks this codec from running in common attack scenarios, such as watching videos or browsing the internet. See &lt;A href="http://www.microsoft.com/technet/security/advisory/954157.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/954157.mspx"&gt;Security Advisory&amp;nbsp;954157&lt;/A&gt; for more information.&lt;/P&gt;
&lt;P&gt;We hope that helps you understand this month’s security updates. We recommend that you apply all security updates but especially please prioritize and deploy MS09-072 as it has a Critical severity rating, an Exploitability Index rate of 1 (“Consistent Exploit Code Likely”), and public Proof of Concept (PoC) code is available. &lt;/P&gt;
&lt;P&gt;Have a safe holiday season and let us know if you have any questions.&lt;/P&gt;
&lt;P&gt;&lt;I&gt;&lt;B&gt;Special thanks to the entire MSRC Engineering team for their work on this month’s security bulletins!&amp;nbsp; Thanks Andrew Roths for the help with this blog post.&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;- Jonathan Ness, MSRC Engineering&lt;/P&gt;
&lt;P&gt;*Posting is provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;/I&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3299184" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/Mitigations/default.aspx">Mitigations</category><category domain="http://blogs.technet.com/srd/archive/tags/rating/default.aspx">rating</category><category domain="http://blogs.technet.com/srd/archive/tags/Attack+Vector/default.aspx">Attack Vector</category><category domain="http://blogs.technet.com/srd/archive/tags/Exploitability/default.aspx">Exploitability</category><category domain="http://blogs.technet.com/srd/archive/tags/Risk+Asessment/default.aspx">Risk Asessment</category></item><item><title>Extended Protection for Authentication</title><link>http://blogs.technet.com/srd/archive/2009/12/08/extended-protection-for-authentication.aspx</link><pubDate>Tue, 08 Dec 2009 17:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3299203</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3299203.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3299203</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;This month, Microsoft is releasing several non-security updates that implement &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/973811.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/973811.mspx"&gt;&lt;FONT size=3 face=Calibri&gt;Extended Protection for Authentication&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; as a mechanism to help safeguard authentication credentials on the Windows platform. These new updates &lt;/FONT&gt;&lt;A title=_GoBack name=_GoBack&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;are not security bulletins, but non-security updates that allow web clients using the Windows HTTP Services, IIS web servers and applications based on the HTTP Protocol Stack (http.sys) to use this feature, which was initially released in August of 2009. After release, developers and administrators still need to take action to configure the feature. More information can be found in &lt;/FONT&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/973811.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/973811.mspx"&gt;Security Advisory 973811&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Extended Protection for Authentication helps protect authentication credentials when using Integrated Windows Authentication. Practically, they prevent an attacker that is able to get access to these credentials through another attack, for instance by soliciting a client to connect to him through social engineering, to use these credentials to log into another server to which the client has access. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=Calibri&gt;&lt;o:p&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;These types of attacks are not new, but can pose a risk in specific deployment scenarios. Hence, this month as well, we released &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/technet/security/advisory/974926.mspx" mce_href="http://www.microsoft.com/technet/security/advisory/974926.mspx"&gt;&lt;FONT color=#0000ff size=3&gt;Security Advisory 974926&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;, which documents how these attacks work, and the different steps Microsoft has taken to help administrators prevent them from being exploited. These include various updates we and our industry partners have released in the past, and the release of the Extended Protection feature that hardens authentication credentials.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;This blog aims to clarify what this new feature really does, and how an administrator can start using it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;o:p&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;FONT size=3&gt;Why Extended Protection for Authentication?&lt;/FONT&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;Microsoft released Extended Protection to allow applications to better safeguard the use of authentication credentials being transferred between a client and server when using Integrated Windows Authentication (IWA). IWA allows a client to authenticate to a server without exposing the user’s password to any potential eavesdropper, typically by using NTLM or Kerberos authentication protocols.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;A certain type of attack, known as credential relaying, is possible when using IWA as deployed in certain scenarios. If an attacker manages to elicit a client to connect to him, that attacker could take advantage of the authentication mechanism and use it to authenticate against a third party server on which the client has an account with identical credentials. In addition, the attacker could even authenticate against a service running on the client itself. However, an attacker could never learn the user’s password.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;FONT size=3&gt;What does Extended Protection for Authentication do?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;Extended Protection for Authentication aims to prevent this type of credential relay. It does this by implementing a protocol based on RFC &lt;/FONT&gt;&lt;A href="http://tools.ietf.org/html/rfc5056" mce_href="http://tools.ietf.org/html/rfc5056"&gt;&lt;FONT color=#0000ff size=3&gt;5056&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;, “On the Use of Channel Bindings to Secure Channels”. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=3&gt;&lt;o:p&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoCommentText&gt;&lt;SPAN style="FONT-SIZE: 11pt"&gt;EAP creates the ability for a client’s authentication to be tied to an outer security channel so that the client authentication only happens under the protection of that same outer channel.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;To see how this works, suppose the client wants to authenticate to a web site.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Here we can establish an outer TLS channel.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;EAP enables a connection to this channel in such a way that the client authentication won’t occur unless the outer TLS has been successfully established.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;To see how this helps thwart credential relaying attacks, let’s take a look as an example.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Let’s say that an attacker would manage to impersonate a server and succeed at having a client connect to him instead. The client would believe he is connecting to e.g. “webmail.contoso.com”. The attacker would take the credentials, set up a connection to another server on which the client has an identical account, for instance “fileserver.contoso.com.” He would then authenticate against that server. &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;At that point in time, if the server has Extended Protection for Authentication enabled, it will validate whether the authentication request was really intended for him, which it is not. In addition, if a TLS channel is present, it will validate whether the credentials were transferred over the same TLS channel. As the client initiates a TLS connection with the attacker, and he subsequently set up a new one with “fileserver.contoso.com,” this will also not match and the server will fail the authentication attempt.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;I style="mso-bidi-font-style: normal"&gt;How do I deploy Extended Protection for Authentication?&lt;o:p&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;Deployment of Extended Protection for Authentication must happen on both the client and server for any given application. If only one side supports the feature, the connection will not benefit from the additional protection offered.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;SPAN style="FONT-SIZE: 11pt"&gt;&lt;o:p&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;Below, we will provide a brief example on how to configure Extended Protection for a scenario that involves Internet Explorer and the Internet Information Services (IIS) web server.&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;The following prerequisites apply:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;On the client, &lt;A href="http://support.microsoft.com/kb/968389" mce_href="http://support.microsoft.com/kb/968389"&gt;&lt;FONT color=#0000ff&gt;KB968389&lt;/FONT&gt;&lt;/A&gt; must be installed, which enables the Extended Protection feature in the Security Support Provider Interface (SSPI). This feature is automatically present on Windows 7 and Windows Server 2008 R2 machines;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;On the client, Internet Explorer cumulative update &lt;A href="http://www.microsoft.com/TECHNET/SECURITY/BULLETIN/MS09-054.MSPX" mce_href="http://www.microsoft.com/TECHNET/SECURITY/BULLETIN/MS09-054.MSPX"&gt;&lt;FONT color=#0000ff&gt;MS09-054&lt;/FONT&gt;&lt;/A&gt; must be installed to enable Internet Explorer to use the feature;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;On the server, both &lt;A href="http://support.microsoft.com/kb/970430" mce_href="http://support.microsoft.com/kb/970430"&gt;&lt;FONT color=#0000ff&gt;KB970430&lt;/FONT&gt;&lt;/A&gt; and &lt;A href="http://support.microsoft.com/kb/973917" mce_href="http://support.microsoft.com/kb/973917"&gt;&lt;FONT color=#0000ff&gt;KB973917&lt;/FONT&gt;&lt;/A&gt; must be installed, which deploy this feature to HTTP.sys and the IIS web server. &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;An administrator must now enable the functionality offered by these updates:&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;On the &lt;B style="mso-bidi-font-weight: normal"&gt;client&lt;/B&gt;, enabling Extended Protection is a machine-wide setting. It will apply to all applications that opt-in to the protection mechanism and use the SSPI for authentication. On Windows 7 and Windows Server 2008 R2 machines, the feature is enabled by default. On older platforms, upon installation of KB968389. Extended Protection must be enabled by setting the value of the registry key &lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Courier New'; FONT-SIZE: 9pt"&gt;HKLM\System\CurrentControlSet\Control\LSA\SuppressExtendedProtection&lt;/SPAN&gt;&amp;nbsp;to 0. In addition, administrators should validate that the&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Courier New'; FONT-SIZE: 9pt"&gt; HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\LmCompatibilityLevel &lt;/SPAN&gt;key is set to 3. This means that the client will only use NTLMv2 authentication, and will use NTLMv2 session security if the server supports it. This is important because Extended Protection for Windows authentication only protects NTLMv2 and Kerberos authentication, not NTLMv1. &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; BACKGROUND: #ffffcc; mso-list: l0 level1 lfo1; mso-add-space: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; COLOR: black; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;On the &lt;B style="mso-bidi-font-weight: normal"&gt;server&lt;/B&gt;, enabling the feature is a per-application setting. In order to protect the IIS web server, Extended Protection must be enabled as well. The instructions differ per IIS version, and more detailed configuration information can be found in &lt;A href="http://support.microsoft.com/kb/973917" mce_href="http://support.microsoft.com/kb/973917"&gt;&lt;FONT color=#0000ff&gt;KB973917&lt;/FONT&gt;&lt;/A&gt;.&lt;BR&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;BR&gt;&lt;/SPAN&gt;On Internet Information Services 7.5, follow these &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;guidelines to enable Extended Protection for Authentication in IIS:&lt;BR style="mso-special-character: line-break"&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.75in; BACKGROUND: #ffffcc; mso-list: l0 level1 lfo1; mso-add-space: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoListParagraph&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;On the taskbar, click &lt;B&gt;Start&lt;/B&gt;, point to &lt;B&gt;Administrative Tools&lt;/B&gt;, and then click &lt;B&gt;Internet Information Services (IIS) Manager&lt;/B&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.75in; BACKGROUND: #ffffcc; mso-list: l0 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;In the &lt;B&gt;Connections&lt;/B&gt; pane, expand the server name, expand &lt;B&gt;Sites&lt;/B&gt;, and then site, application or Web service for which you want to enable Extended Protection for Windows authentication. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.75in; BACKGROUND: #ffffcc; mso-list: l0 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;3.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;Scroll to the &lt;B&gt;Security&lt;/B&gt; section in the &lt;B&gt;Home&lt;/B&gt; pane, and then double-click &lt;B&gt;Authentication&lt;/B&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.75in; BACKGROUND: #ffffcc; mso-list: l0 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;4.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;In the &lt;B&gt;Authentication&lt;/B&gt; pane, select &lt;B&gt;Windows Authentication&lt;/B&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.75in; BACKGROUND: #ffffcc; mso-list: l0 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;5.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;Click &lt;B&gt;Enable&lt;/B&gt; in the &lt;B&gt;Actions&lt;/B&gt; pane. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; BACKGROUND: #ffffcc; mso-list: l0 level1 lfo1; mso-add-space: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoListParagraph&gt;&lt;IMG src="http://blogs.technet.com/photos/swiblog/images/3299204/original.aspx" mce_src="http://blogs.technet.com/photos/swiblog/images/3299204/original.aspx"&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.75in; BACKGROUND: #ffffcc; mso-list: l0 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;Click &lt;B&gt;Advanced Settings&lt;/B&gt; in the &lt;B&gt;Actions&lt;/B&gt; pane. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.75in; BACKGROUND: #ffffcc; mso-list: l0 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;When the &lt;B&gt;Advanced Settings&lt;/B&gt; dialog box appears, select one of the following options in the &lt;B&gt;Extended Protection&lt;/B&gt; drop-down menu: &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 1.25in; BACKGROUND: #ffffcc; mso-list: l0 level2 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;a.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;Selecting &lt;B&gt;Accept&lt;/B&gt; will enable a connection terminating on the IIS server to&lt;/SPAN&gt; benefit from Extended Protection if the client has been configured to support it. Clients that have not enabled the feature will still be allowed to connect, but will not benefit from the additional protection.&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 1.25in; BACKGROUND: #ffffcc; mso-list: l0 level2 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;b.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;Selecting &lt;B&gt;Required&lt;/B&gt; will require clients to use Extended Protection. If they do not support it, any authentication attempts against IIS using IWA will fail.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; BACKGROUND: #ffffcc; mso-list: l0 level1 lfo1; mso-add-space: auto; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoListParagraph&gt;&lt;IMG src="http://blogs.technet.com/photos/swiblog/images/3299205/original.aspx" mce_src="http://blogs.technet.com/photos/swiblog/images/3299205/original.aspx"&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI style="LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt; BACKGROUND: #ffffcc; COLOR: black; mso-list: l0 level1 lfo1; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; tab-stops: list .5in" class=MsoNormal&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;Click OK to close the &lt;B&gt;Advanced Settings&lt;/B&gt; dialog box.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;If a user enables Extended Protection for Authentication, and attempts to connect to a server that does not support the feature, that authentication attempt will still succeed. &lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;I style="mso-bidi-font-style: normal"&gt;Can I support Extended Protection in my application?&lt;o:p&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;This depends on the protocol. Many protocols can be protected, but some cannot. For instance, RPC does not support Extended Protection for Authentication, but can also be protected by enabling &lt;A href="http://msdn.microsoft.com/en-us/library/cc243616(PROT.13).aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc243616(PROT.13).aspx"&gt;&lt;FONT color=#0000ff&gt;confidentiality/integrity&lt;/FONT&gt;&lt;/A&gt;. &lt;BR&gt;&lt;BR&gt;Applications implementing other protocols, such as HTTP, can definitely benefit from this feature. We encourage developers to implement this feature. If your application uses the WinHTTP or WinINET programming interfaces, then you are indirectly already benefiting from this protection, as updates for both APIs are now available. Developers can find the SSPI headers for Extended Protection &lt;A href="http://msdn.microsoft.com/en-us/library/dd919963(VS.85).aspx" mce_href="http://msdn.microsoft.com/en-us/library/dd919963(VS.85).aspx"&gt;&lt;FONT color=#0000ff&gt;here&lt;/FONT&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;Thanks to Mark Novak, Larry Zhu, Paul Leach and Paul Miller for their design and implementation work on this feature. Thanks also go out to Andrew Roths from the MSRC Engineering team for his technical feedback on this blog post.&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;-Maarten Van Horenbeeck, MSRC Program Manager&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;*Posting is provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;STRONG&gt;&amp;nbsp;12/8/09 Update: Updated&amp;nbsp;the links to security advisories 973811 and 974926.&lt;/STRONG&gt;&lt;/P&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3299203" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/network+protocol/default.aspx">network protocol</category><category domain="http://blogs.technet.com/srd/archive/tags/NTLM/default.aspx">NTLM</category><category domain="http://blogs.technet.com/srd/archive/tags/Risk+Asessment/default.aspx">Risk Asessment</category></item><item><title>SEHOP per-process opt-in support in Windows 7</title><link>http://blogs.technet.com/srd/archive/2009/11/20/sehop-per-process-opt-in-support-in-windows-7.aspx</link><pubDate>Sat, 21 Nov 2009 00:09:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3295505</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3295505.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3295505</wfw:commentRss><description>&lt;P&gt;&lt;A href="http://blogs.technet.com/srd/archive/2009/02/02/preventing-the-exploitation-of-seh-overwrites-with-sehop.aspx" mce_href="http://blogs.technet.com/srd/archive/2009/02/02/preventing-the-exploitation-of-seh-overwrites-with-sehop.aspx"&gt;In a previous blog post&lt;/A&gt; we discussed the technical details of Structured Exception Handler Overwrite Protection (SEHOP) which is an exploit mitigation feature that was first introduced in Windows Vista SP1 and Windows Server 2008 RTM. SEHOP prevents attackers from being able to use the Structured Exception Handler (SEH) overwrite exploitation technique when attempting to exploit certain types of software vulnerabilities. SEHOP is enabled&amp;nbsp;by default system-wide on Windows Server 2008 and disabled by default on Windows Vista. These are also the defaults settings in Windows Server 2008 R2 (enabled) and Windows 7 (disabled).&lt;/P&gt;
&lt;P&gt;Although some applications have had compatibility problems with SEHOP, the vast majority of applications work without issue. In order to make it possible for compatible applications to take advantage of SEHOP, we have added support in Windows 7 that allows SEHOP to be enabled or disabled on a per-process basis. This setting will override the system default policy when it is used. SEHOP can be enabled for a process by setting the new &lt;FONT face="Courier New"&gt;DisableExceptionChainValidation&lt;/FONT&gt; Image File Execution Option (IFEO) to 0 (or disabled by setting it to 1). For example, &lt;A href="http://blogs.msdn.com/ieinternals/archive/2009/06/18/Enhanced-IE-Security-with-SEHOP.aspx" mce_href="http://blogs.msdn.com/ieinternals/archive/2009/06/18/Enhanced-IE-Security-with-SEHOP.aspx"&gt;SEHOP can be enabled for Internet Explorer&lt;/A&gt; on Windows 7 by applying the following registry script*:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;Windows Registry Editor Version 5.00&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe]&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;"DisableExceptionChainValidation"=dword:00000000&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Users running Windows Vista SP1+ or Windows 7 who would like to enable SEHOP for all applications (which we strongly recommend) can do so by installing the following FixIt:&lt;/P&gt;
&lt;P align=center&gt;&lt;A href="http://go.microsoft.com/?linkid=9646972" mce_href="http://go.microsoft.com/?linkid=9646972"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image002 border=0 alt=clip_image002 src="http://blogs.technet.com/blogfiles/srd/WindowsLiveWriter/SEHOPperprocessoptinsupportinWindows7_E350/clip_image002_884da70b-fd33-47d3-bb6d-91571e110fb7.jpg" width=143 height=60 mce_src="http://blogs.technet.com/blogfiles/srd/WindowsLiveWriter/SEHOPperprocessoptinsupportinWindows7_E350/clip_image002_884da70b-fd33-47d3-bb6d-91571e110fb7.jpg"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P align=center&gt;&lt;A href="http://go.microsoft.com/?linkid=9646972" mce_href="http://go.microsoft.com/?linkid=9646972"&gt;Enable SEHOP for all applications&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If enabling SEHOP for all applications leads to a problem with a specific application, the new IFEO in Windows 7 and Windows Server 2008 R2 can be used to disable SEHOP for just the affected process as described above. Alternatively, you can disable SEHOP for all applications by following the steps described in &lt;A href="http://support.microsoft.com/kb/956607" mce_href="http://support.microsoft.com/kb/956607"&gt;KB956607&lt;/A&gt;. If you cannot enable SEHOP for all applications we strongly recommend enabling SEHOP for all internet facing applications, such as your preferred browser and mail client.&lt;/P&gt;
&lt;P&gt;Matt Miller, MSEC Science&lt;/P&gt;
&lt;P&gt;* If you are running a 64-bit version of Windows, you will need to set the IFEO under the Wow6432Node portion of the registry which corresponds to the registry hive used by 32-bit applications (e.g. HKLM\Software\Wow6432Node\...)&lt;/P&gt;
&lt;P&gt;*Postings are provided "AS IS" with no warranties, and confers no rights.*&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3295505" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/Mitigations/default.aspx">Mitigations</category><category domain="http://blogs.technet.com/srd/archive/tags/exploitation/default.aspx">exploitation</category><category domain="http://blogs.technet.com/srd/archive/tags/Security+Science/default.aspx">Security Science</category><category domain="http://blogs.technet.com/srd/archive/tags/Defense-in-depth/default.aspx">Defense-in-depth</category></item><item><title>Details on the License Logging Service vulnerability</title><link>http://blogs.technet.com/srd/archive/2009/11/10/details-on-the-license-logging-service-vulnerability.aspx</link><pubDate>Tue, 10 Nov 2009 18:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3292862</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3292862.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3292862</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Today, we released MS09-064 which addresses a vulnerability in the License Logging Service.&amp;nbsp; In this post, we provide some background on the service and the severity of the underlying vulnerability.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Background&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;License Logging Service (LLS) is a feature that was originally designed to help customers manage licenses for Microsoft server products licensed in the Server Client Access License (CAL) model. See &lt;A href="http://support.microsoft.com/kb/824196" mce_href="http://support.microsoft.com/kb/824196"&gt;http://support.microsoft.com/kb/824196&lt;/A&gt; for more details.&amp;nbsp; The service has been removed from the Windows Server product line starting with Windows Server 2008. Of the remaining supported platforms this issue only affects the Windows Server 2000 version of LLS.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Why is the bulletin severity “critical”?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;The bulletin is marked as “critical” for several reasons:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;The service is enabled by default on Windows Server 2000.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;It is accessible by anonymous network connection.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;The underlying issue can lead to extensive heap memory corruption.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;What are the mitigating factors?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;There are two circumstances though that may lower its severity significantly.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;First, the most common scenario of LLS feature calls for managing CALs within trusted enterprise environment, which in most cases means that the network access to the server hosting LLS will be limited to the local segment of a network, usually separated from the Internet by a firewall, proxy server, or other barrier.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Second, the issue leads to a memory corruption, which based on our analysis is very difficult to turn into remote code execution.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Technical details&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;The root cause of the problem is a lack of string verification for the presence of NULL-terminating characters. An unverified string lacking NULL-termination can be passed to a function, which performs following steps:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;calculate length of the unverified string,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;allocate buffer for a new string, using the calculated length and the length of some other string,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;concatenate two strings in the new buffer.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Since the length calculation of the unverified string can run beyond the string buffer (because of missing NULL termination), we may end up with four different scenarios depending on the heap memory layout at the time of execution:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;During the string length calculation, code runs beyond string buffer and hits an unallocated memory page, causing read access violation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;During the string length calculation, code finds a NULL terminating character beyond the string buffer, returning an exaggerated length. The terminating character falls at lower address than the memory block allocated for the new string. The “exaggerated” string is concatenated with the other string in the new buffer, causing no memory access exception, because the length of the new buffer was calculated using the “exaggerated” length.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;3.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;In scenario 2, another thread owning the block of memory containing the NULL-terminating character incorrectly used for the length calculation, changes the content of memory right after the length calculation, but before string concatenation. This causes a new buffer overflow during concatenation, leading to semi-controlled heap corruption and/or write access violation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;4.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;In scenario 2, the memory block allocated for the new string includes the NULL-terminating character. The character then gets overwritten during concatenation process, leading to extensive memory copying and causing write access violation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Scenario 3 relies on a very narrow race condition and thus any attempt to exploit it is likely to be unreliable.&amp;nbsp; The only scenario leading to a potentially reliable exploit is scenario 4.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;This leads us to a conclusion that real-life exploitation of this vulnerability will be less likely.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;-Greg, MSRC Engineering&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3292862" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/Exploitability/default.aspx">Exploitability</category><category domain="http://blogs.technet.com/srd/archive/tags/License+Logging+Service/default.aspx">License Logging Service</category><category domain="http://blogs.technet.com/srd/archive/tags/LLS/default.aspx">LLS</category><category domain="http://blogs.technet.com/srd/archive/tags/MS09-064/default.aspx">MS09-064</category></item><item><title>Vulnerability in Web Services on Devices (WSD) API</title><link>http://blogs.technet.com/srd/archive/2009/11/10/vulnerability-in-web-services-on-devices-wsd-api.aspx</link><pubDate>Tue, 10 Nov 2009 18:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3292863</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3292863.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3292863</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-063.mspx" mce_href="http://www.microsoft.com/technet/security/Bulletin/MS09-063.mspx"&gt;&lt;FONT color=#0000ff&gt;MS09-063&lt;/FONT&gt;&lt;/A&gt; addresses a critical vulnerability (CVE-2009-2512) in the Web Services on Devices (WSD) API. Web Services on Devices allows a computer to discover and access a remote device and its associated services across a network. It supports device discovery, description, control, and eventing. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;The WSD API functionality is implemented in the WSDApi.dll module in Windows, and is used by several services and applications. The API is also &lt;A href="http://msdn.microsoft.com/en-us/library/aa826001(VS.85).aspx" mce_href="http://msdn.microsoft.com/en-us/library/aa826001(VS.85).aspx"&gt;&lt;FONT color=#0000ff&gt;documented on MSDN&lt;/FONT&gt;&lt;/A&gt; for 3&lt;SUP&gt;rd&lt;/SUP&gt; party developers to use. Therefore, a comprehensive list of services and application that are vulnerable to this issue is hard to define, but here are some examples:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Print Spooler service&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Function Discovery Resource Publication service&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Function Discovery Provider Host service&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Windows Network Projector&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;There are mitigating factors that limit the scenarios where the vulnerability can be exploited. We will describe the vulnerability and mitigating factors in more detail in this blog post.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;What is the issue?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;A long header value within a WSD message can lead to stack corruption within the process hosting WSDApi.dll. This can cause the service or application to crash, or could lead to Remote Code Execution. To be clear, the vulnerability is in the Windows module used to interact with devices that support Web Services on Devices, and does not affect the devices themselves.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;What platforms are affected?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Windows Vista and Windows Server 2008 are affected. WSDAPI was introduced in Windows Vista and hence earlier versions of Windows are not vulnerable.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Only systems with the WSD TCP ports active and listening are vulnerable to the most likely attack vector. Whether a system has WSD ports active and listening depends on the system configuration and applications that are installed. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;What are the attack vectors?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;By default, WSDAPI will listen on TCP ports 5357 and 5358. The Windows Firewall will allow messages in to these ports if the interface firewall profile is anything other than Public. This means under non-Public profiles (e.g. Private or Domain) the vulnerability can be reached by remote, unauthenticated users.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;For an attacker to be able to trigger the vulnerability on a target, they need to know the WSD Address value for the target, which is a UUID (Universally Unique Identifier). This value is automatically sent in broadcast UDP messages to port 3702 (WS-Discovery) in an effort to discover devices that support WSD. Being broadcast UDP the message will only be visible to attackers on the same subnet. Attackers on other subnets, or on the Internet, will not be able to launch attacks against distant targets using this approach.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;A system could also be exploited by a malicious device which responds to a client computer using WSDAPI. It is possible for the user to manually enter the URL of a device to connect to, in which case the device could respond with a malformed message and trigger the vulnerability. This requires user-interaction and social engineering, however.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Mitigating factors&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;As explained above, the most common exploit scenario requires that the attacker is on the same subnet as the target system in order for the target’s WSD Address to be discovered.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;The default Windows Firewall rules limit inbound WSD messages to sources on the local subnet for Private and Domain profiles. The Public firewall profile blocks WSD messages completely.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;If WSD functionality is not needed, the &lt;A href="http://www.microsoft.com/technet/security/Bulletin/MS09-063.mspx" mce_href="http://www.microsoft.com/technet/security/Bulletin/MS09-063.mspx"&gt;&lt;FONT color=#0000ff&gt;security bulletin&lt;/FONT&gt;&lt;/A&gt; provides information on using the Windows Firewall to block the inbound and outbound ports used to trigger this vulnerability. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;I’d like to thank Rob Hain and Dan Driscoll from the WSD team, and Kevin Brown from MSRC Engineering for their work on this issue.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-bidi-language: AR-SA"&gt;- Mark Wodrich, MSRC Engineering&lt;/SPAN&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3292863" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/WSD/default.aspx">WSD</category><category domain="http://blogs.technet.com/srd/archive/tags/WSDAPI/default.aspx">WSDAPI</category><category domain="http://blogs.technet.com/srd/archive/tags/MS09-063/default.aspx">MS09-063</category></item><item><title>Font Directory Entry Parsing Vulnerability In win32k.sys</title><link>http://blogs.technet.com/srd/archive/2009/11/10/font-directory-entry-parsing-vulnerability-in-win32k-sys.aspx</link><pubDate>Tue, 10 Nov 2009 18:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3292881</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3292881.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3292881</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;MS09-065 addresses a vulnerability (CVE-2009-2514) in the font parsing subsystem of win32k.sys.&amp;nbsp; If not addressed, this vulnerability could allow an attacker to bluescreen (DoS) the machine (best case scenario) or run code of his/her choice, possibly in the context of the kernel (worst case scenario).&amp;nbsp; &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;In this blog entry, I'll attempt to answer a few questions regarding the vulnerability addressed in this month’s win32k.sys security update:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;What is the issue?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;An integer-wrapping vulnerability exists in the font parsing subsystem within win32k.sys, which is responsible for constructing a table of directory entries. &amp;nbsp;The integer wrap can occur when adding a directory entry’s’ offset and size members, which could lead to improper memory access in subsequent code.&amp;nbsp; This improper memory access would commonly be observed in the form of a Read Access Violation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;The severity rating of critical was chosen since the vulnerable code is exposed through Internet Explorer and can be exercised without user interaction/notification.&amp;nbsp; It has also been given an &lt;A href="http://technet.microsoft.com/en-us/security/cc998259.aspx"&gt;Exploitability Index&lt;/A&gt; rating of 1.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;What platforms are affected?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Users of Windows 2000, Windows XP, and Windows Server 2003 are affected by this vulnerability.&amp;nbsp; Windows Vista, Windows 7, Windows Server 2008, and Windows 2008 R2 users are not affected. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;What are the attack vectors?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Remote attack vectors (worst case scenario is Remote code Execution):&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Consolas; FONT-SIZE: 10pt; mso-fareast-font-family: Consolas; mso-bidi-font-family: Consolas"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Malicious fonts (TTF’s) delivered within .eot files hosted on malicious web sites which are rendered in all versions of Internet Explorer by default.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Consolas; FONT-SIZE: 10pt; mso-fareast-font-family: Consolas; mso-bidi-font-family: Consolas"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Malicious office documents e-mailed to victims with social engineering to entice the victim to open the document which contains a malformed embedded font which would then be rendered upon opening the Office document (PowerPoint and Word documents are the most likely attack vectors).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Local attack vectors (worst case scenario is Local Elevation of Privilege):&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Consolas; FONT-SIZE: 10pt; mso-fareast-font-family: Consolas; mso-bidi-font-family: Consolas"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Malicious fonts (TTF’s) delivered to win32k.sys by an authenticated user in a multi-user environment (Terminal Services (TS)) scenario.&amp;nbsp;Such scenarios might abuse AddFontResource() to achieve this.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;How do I protect myself?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;The best option for protecting against this vulnerability is to apply the update for MS09-065.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;If you are unable to apply the update, another option is to disable support for parsing/loading embedded fonts in IE.&amp;nbsp; The side effect of this approach is that it will cause web sites which make use of embedded font technology to fail to render properly.&amp;nbsp; The steps involved in disabling support for parsing embedded fonts in IE are as follows: &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Interactive&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Launch Internet Explorer&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;On the ‘Tools’ Menu select ‘Internet Options’.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Click the ‘Security’ Tab.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;To change the setting for the ‘Internet’ zone select ‘Internet’ and press the ‘Custom Level’ button.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Scroll down to the ‘Downloads’ section and select ‘Prompt’ or ‘Disable’ for the ‘Font Download’ security setting.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Press OK to close the ‘Security Settings’ dialog box.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Press OK to close the ‘Internet Options’ dialog box.&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;IMG style="WIDTH: 431px; HEIGHT: 487px" title="Disable IE Font Parsing" alt="Disable IE Font Parsing" src="http://blogs.technet.com/photos/swiblog/images/3292866/original.aspx" width=431 height=487 mce_src="http://blogs.technet.com/photos/swiblog/images/3292866/original.aspx"&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Group Policy&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;NOTE:&amp;nbsp; The Group Policy MMC snap-in can be used to set policy for a machine, for an organizational unit or an entire domain.&amp;nbsp; It is assumed that the reader will know how to deploy the steps below for their particular environment.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Open the group policy management and configure it to work with the appropriate group policy object (i.e. local machine, OU or domain GPO).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Navigate to the following node:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1.5in; mso-list: l0 level2 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;User Configuration -&amp;gt; Windows Settings -&amp;gt; Internet Explorer Maintenance -&amp;gt; Security.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Double click ‘Security Zones and Content Rating’.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;On the ‘Security Zones and Content Rating’ dialog box select ‘Import the current security zones and privacy settings’ and then click the ‘Modify settings’ button.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;NOTE:&amp;nbsp; This will create a group policy for Internet Explorer based on the settings of the currently logged in user.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;On the ‘Internet Properties’ dialog box ensure the ‘Internet’ zone is selected and then press ‘custom level’.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Scroll down to ‘Downloads’ and set ‘Font Download’ to ‘Prompt’ or ‘Disable’.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Press OK to return to the ‘Internet Properties’ dialog box.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;On the “Internet Properties’ dialog box select the ‘Local Intranet’ zone and then press ‘custom level’. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Scroll down to ‘Downloads’ and set ‘Font Download’ to ‘Prompt’ or ‘Disable’.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Press OK to return to the ‘Internet Properties’ dialog box.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Press OK to return to the ‘Security Zones and Content Ratings’ dialog box.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Press OK to return to the group policy management console.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; FONT-SIZE: 10pt; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Refresh the group policy on all machines or wait for the next scheduled group policy refresh interval for the settings to take effect.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Managed Deployment Script&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;This security setting can be manually entered into the registry by creating a registry script and importing it either by double clicking it or running regedit.exe as part of a logon or machine startup script.&amp;nbsp; For managed deployments Regedit.exe can be used to import a registry script silently with the ‘-s’ switch.&amp;nbsp; For more information on regedit command line switches refer to: &lt;A href="http://support.microsoft.com/kb/q82821/"&gt;&lt;FONT color=#0000ff&gt;http://support.microsoft.com/kb/q82821/&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;To set this setting to ‘Prompt’ for the Internet and Local Intranet Zones paste the following text into a .REG file and then import the .REG file on managed machines as part of your organizations managed deployment process:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Windows Registry Editor Version 5.00&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;; Zone 1 is the local intranet zone&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;; 1604 is the Font download policy&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;; dword:00000001 sets the policy to prompt&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;"1604"=dword:00000001&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;; Zone 3 is the internet zone&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;"1604"=dword:00000001&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;To set this setting to ‘Disable’ for the Internet and Local Intranet Zones paste the following text into a .REG file and then import the .REG file on managed machines as part of your organizations managed deployment process:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Windows Registry Editor Version 5.00&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;; Zone 1 is the local intranet zone&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;; 1604 is the Font download policy&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;; dword:00000003 sets the policy to disable&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;"1604"=dword:00000003&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;; Zone 3 is the internet zone&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;"1604"=dword:00000003&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Big thanks to Robert Hensing from the MSRC Engineering Team for his work on defensive workarounds for this issue as well as to Andrew Roths from the MSRC Engineering Team.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;-Brian Cavenah, MSRC Engineering&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3292881" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/srd/archive/tags/Internet+Explorer+_2800_IE_2900_/default.aspx">Internet Explorer (IE)</category><category domain="http://blogs.technet.com/srd/archive/tags/Exploitability/default.aspx">Exploitability</category><category domain="http://blogs.technet.com/srd/archive/tags/Font/default.aspx">Font</category><category domain="http://blogs.technet.com/srd/archive/tags/MS09-065/default.aspx">MS09-065</category><category domain="http://blogs.technet.com/srd/archive/tags/TTF/default.aspx">TTF</category></item><item><title>Announcing the release of the Enhanced Mitigation Evaluation Toolkit</title><link>http://blogs.technet.com/srd/archive/2009/10/27/announcing-the-release-of-the-enhanced-mitigation-evaluation-toolkit.aspx</link><pubDate>Tue, 27 Oct 2009 16:21:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3289548</guid><dc:creator>swiblog</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/srd/comments/3289548.aspx</comments><wfw:commentRss>http://blogs.technet.com/srd/commentrss.aspx?PostID=3289548</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;Even as you read this, people around the world are hunting for vulnerabilities in software applications.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Odds are some of them will be successful.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Depending on their motives and what they find, your software and systems may be put at risk.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So how do you protect your software from unknown vulnerabilities that may or may not exist?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;One option is to use security mitigations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Microsoft offers a number of different mitigation technologies that are designed to make it more difficult for an attacker to exploit vulnerabilities in a given piece of software.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Take a look at Michael Howard’s article “Protecting Your Code with Visual C++ Defenses” (&lt;A href="http://msdn.microsoft.com/en-us/magazine/cc337897.aspx" mce_href="http://msdn.microsoft.com/en-us/magazine/cc337897.aspx"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT color=#0000ff face="Times New Roman"&gt;http://msdn.microsoft.com/en-us/magazine/cc337897.aspx&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;) for a brief overview of some of these technologies.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;To help on this front, we are announcing the initial release of a new utility called the Enhanced Mitigation Evaluation Toolkit (EMET).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Version 1.0.2 is now available, free of charge at the Microsoft Download Center (&lt;A href="http://go.microsoft.com/fwlink/?LinkID=162309" mce_href="http://go.microsoft.com/fwlink/?LinkID=162309"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT color=#0000ff face="Times New Roman"&gt;http://go.microsoft.com/fwlink/?LinkID=162309&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This utility builds on our current offerings in several key ways:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Until now, many of the available mitigations have required for an application to be manually opted in and recompiled.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;EMET changes this by allowing a user to opt in applications via a simple command-line utility without recompilation.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is especially handy for deploying mitigations on software that was written before the mitigations were available and when source code is not available.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;EMET provides a higher degree of granularity by allowing mitigations to be applied on a per process basis.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;There is no need to enable an entire product or suite of applications.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is helpful in situations where a process is not compatible with a particular mitigation technology.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;When that happens, a user can simply turn EMET off for that process.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;3.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Mitigations that have previously been limited to up-level versions of Microsoft Windows now ship with EMET and are available down-level.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Users can benefit from these mitigations without the need to upgrade their systems.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: Arial"&gt;&lt;SPAN style="mso-list: Ignore"&gt;4.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;EMET is a living tool designed to be updated as new mitigation technologies become available.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This provides a chance for users to try out and benefit from mitigations before they are included in the next versions of our products.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It also gives users the opportunity to provide feedback and help guide the future of mitigation technologies in Microsoft products.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H1 style="MARGIN: 24pt 0in 0pt"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; COLOR: windowtext; FONT-SIZE: 12pt"&gt;Supported Mitigations&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;This initial release of EMET is primarily focused on providing an extensible framework that will have future mitigations added to it.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;A total of four mitigations are also being included with this release and are listed below.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We will provide announcements as future mitigations are added.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If you have ideas about mitigations you’d like to see (whether they already exist or not) feel free to contact us.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;SEHOP&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;This mitigation performs Structured Exception Handling (SEH) chain validation and breaks SEH overwrite exploitation techniques. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Take a look at the following SRD blog post for more information: &lt;A href="http://blogs.technet.com/srd/archive/2009/02/02/preventing-the-exploitation-of-seh-overwrites-with-sehop.aspx" mce_href="http://blogs.technet.com/srd/archive/2009/02/02/preventing-the-exploitation-of-seh-overwrites-with-sehop.aspx"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;&lt;FONT color=#0000ff face="Times New Roman"&gt;http://blogs.technet.com/srd/archive/2009/02/02/preventing-the-exploitation-of-seh-overwrites-with-sehop.aspx&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;With this protection in place, the msvidctl exploit we already blogged about (&lt;A href="http://blogs.technet.com/srd/archive/2009/07/28/msvidctl-ms09-032-and-the-atl-vulnerability.aspx" mce_href="http://blogs.technet.com/srd/archive/2009/07/28/msvidctl-ms09-032-and-the-atl-vulnerability.aspx"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;http://blogs.technet.com/srd/archive/2009/07/28/msvidctl-ms09-032-and-the-atl-vulnerability.aspx&lt;/SPAN&gt;&lt;/A&gt;) would have failed.&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Dynamic DEP&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Data Execution Prevention (DEP) is a memory protection mitigation that marks portions of a process’ memory non-executable.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This makes it more difficult to an attacker to exploit memory corruption vulnerabilities.&amp;nbsp; For more information on what DEP is and how it works, take a look at the two part SRD blog available at &lt;A href="http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-1.aspx" mce_href="http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-1.aspx"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-1.aspx&lt;/SPAN&gt;&lt;/A&gt; and &lt;A href="http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx" mce_href="http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx"&gt;&lt;SPAN style="mso-bidi-font-family: Arial"&gt;http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx&lt;/SPAN&gt;&lt;/A&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&amp;nbsp;NULL page allocation&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;This blocks attackers from being able to take advantage of NULL dereferences in user mode.&amp;nbsp; It functions by allocating the first page of memory before the program starts.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Right now the exploitation techniques for these types of vulnerabilities are only theoretical.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;However, this mitigation will protect you even if that changes. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Please note this protection does not impact kernel mode NULL dereferences as the current version of EMET only supports user mode mitigations.&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;STRONG&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&amp;nbsp;Heap spray allocation&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Heap spraying is an attack technique that involves filling a process’ heap with specially crafted content (typically including shellcode) to aid in exploitation.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Right now, many attackers rely on their content being placed at a common set of memory addresses.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;This mitigation is designed to pre-allocate those memory addresses and thus block these common attacks.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Please note that it only aims to break current exploit that take advantage of these common addresses.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It is not a general mitigation for the larger heap spraying attack.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;That said, if attackers do change the addresses they use, EMET users can change the addresses &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H1 style="MARGIN: 24pt 0in 0pt"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; COLOR: windowtext; FONT-SIZE: 12pt"&gt;A Note about Application Compatibility&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Security mitigations carry an application compatibility risk with them.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Some applications rely on precisely the behavior that the mitigations block.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For this reason mitigations are typically turned off by default and require opt-in from a developer before they are enabled.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;While EMET allows users to override this, it is important to be aware of the risk.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;EMET is intended for tech savvy users such as IT professionals and security researchers who can troubleshoot issues that these mitigations may introduce.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We also recommend testing your applications and use scenarios with these mitigations prior to deploying them on any production systems.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H1 style="MARGIN: 24pt 0in 0pt"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; COLOR: windowtext; FONT-SIZE: 12pt"&gt;Feedback&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;We encourage you to download and try out the tool.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If you have any feedback on your experiences with the tool, you can reach us at &lt;B&gt;&lt;SPAN style="COLOR: #95b3d7"&gt;switech@microsoft.com &lt;/SPAN&gt;&lt;/B&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;Special thanks to Matt Miller for his assistance with EMET.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;-&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Fermin J. Serna and Andrew Roths, MSRC Engineering&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3289548" width="1" height="1"&gt;</description></item></channel></rss>