Incomplete Microsoft Patch Left Machines Exposed To Stuxnet LNK Vulnerability
msm1267 writes: A five-year-old Microsoft patch for the .LNK vulnerability exploited by Stuxnet failed to properly protect Windows machines, leaving them exposed to exploits since 2010. Microsoft today is expected to release a security bulletin, MS15-020, patching the vulnerability (CVE-2015-0096). It is unknown whether there have been public exploits of patched machines. The original LNK patch was released Aug. 2, 2010. "That patch didn't completely address the .LNK issue in the Windows shell, and there were weaknesses left behind that have been resolved in this patch," said Brian Gorenc, manager of vulnerability research with HP's Zero Day Initiative. Gorenc said the vulnerability works on Windows machines going back to Windows XP through Windows 8.1, and the proof of concept exploit developed by Heerklotz and tweaked by ZDI evades the validation checks put in place by the original Microsoft security bulletin, CVE-2010-2568.
This is going to get ugly
Who wants to bet they left a backdoor in there on purpose
Microbama.
How Microsoft was dropped
I really think now that Linux is the future
Is this why there are torrents out there with a several hundred megabyte file with the name of a TV show ending in .mp4.lnk ?
Everyone knows Microsoft and apple just do the governments bidding, and stuxnet is clearly made by the American government. .lnk , yeah right. it was left in there intentionally.
and the Americans are all being played by the Chinese who can do whatever they want, because in Communist China, the government thinks for you, and the rest of the world.
Failed to patch the bug
Just like all the bugs that are still present in the preview parsers.
Get over it.
Learn Chinese.
Learn the Koran
Use it against them!
I don't even read Slashdot "stories" about Microsoft anymore, because most are just obvious "troll" or click-bait aimed at the anti-microsofties that prevail at Slashdot.
Soylentnews.com is a great site.
If you want news from today, you have to come back tomorrow.
Linux. Had to rub it in.
Doesn't exist on so many levels it is now passé.
Full details about how the 2010 patch failed are now available. Looks like they tried to do a whitelist check for approved CPL files, but it didn't work. There's a video too, although a video showing how to use regedit is only so useful. http://h30499.www3.hp.com/t5/H...
The way I see it, it's quite feasible that the vulnerability was deliberately left in to provide a back door for the US government agencies to exploit. Only now that stuxnet and similar are becoming widely publicised are Microsoft closing that door.
Here at the NSA, we would like to extend a heartfelt thank you to Microsoft for the incomplete patch. Not that we had anything at all to do with STUXNET. No, nothing at all. Nor anyone else in the U.S. government from any other agencies, nor the defense department.
Again, THANK YOU, Microsoft.
Howdy. Its NSA here, You can patch the hole now, Stux is no use to us anymore.
Micro$oft: Ok, wilco. See You at lunch.
why all my centrifuges just blew up.
Curse You Microsoft!
Harrison's Postulate - "For every action there is an equal and opposite criticism"