myITforum.com

Welcome to myITforum.com Sign in | Join | Help
in Search

Harry Waldron - My IT Forums Blog

Sharing Security Developments, and Best Practices for corporate and home users

Backdoor.Hesive - Zero Day MS Access Jet Engine Exploit

  Please be careful with all email messages containing Microsoft Access attachments. This new exploit capitalizes on an unpatched MS Jet Engine vulnerability that creates a compromise to system security until the Trojan Horse is removed. 

While this new zero day attack is very rare, it could could surprise individuals if we were massively spammed in the wild, Microsoft Access data base email attachments are usually thought of as being safe to open.  Thus we should always be cautious on ANY attachment type and the best practice is to never open attachments regardless of whether they appear safe or not. 

Backdoor.Hesive - Zero Day MS Jet Engine Exploit
http://secunia.com/virus_information/21954/hesive/

Backdoor.Hesive is a Trojan horse that opens a back door on the compromised computer and allows a remote attacker unauthorized access. The Trojan may arrive as a Microsoft Access file that exploits the Microsoft Jet Database Engine Malformed Database File Buffer Overflow Vulnerability (described in Bugtraq ID 12960).


Microsoft Jet Database Engine Malformed Database File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/12960/info

Solution: Currently we are not aware of any vendor-supplied patches for this issue

Allows the remote attacker the ability to perform the following actions:

List active ports
List processes, services, and threads
Download and execute remote files
Upload files
Run a system shell
Modify registry values
End processes
Get system information
Get network information
Post collected data to hostile web site

Comments

No Comments
Powered by Community Server (Commercial Edition), by Telligent Systems