Home > Stuxnet/Duqu > Duqu Installer Contained Microsoft Word Zero-Day Exploit
Duqu Installer Contained Microsoft Word Zero-Day Exploit
Posted on 9 November 2011 by c0decstuff
Earlier this week Symantec released an update on Duqu. Apparently an installer was found for Duqu (dubbed Stuxnet II) that used a Microsoft Zero-day:
“The installer file is a Microsoft Word document (.doc) that exploits a previously unknown kernel vulnerability that allows code execution. We contacted Microsoft regarding the vulnerability and they’re working diligently towards issuing a patch and advisory. When the file is opened, malicious code executes and installs the main Duqu binaries.”
So far Duqu infections have been confirmed in six organizations in eight countries. The locations include France, India, Iran and Sudan.
In a short release on Tuesday, Microsoft stated that they know of the threat and are working on getting it patched, “We are working diligently to address this issue and will release a security update for customers.”
Category Article Stuxnet/Duqu
Labels
- Android (1)
- Aplication (14)
- Backdoored (2)
- Browser (1)
- Cloud (1)
- Exploitation (1)
- Exploits (7)
- Facebook (2)
- forensics (2)
- Hacking (11)
- Hijacking (1)
- Honeypot (1)
- HTML5 (1)
- ios (2)
- Jailbreak (2)
- Linux (1)
- Malware (5)
- metasploit (2)
- Meterpreter (1)
- Movie (1)
- Networking (1)
- News (2)
- password attack (1)
- Python (1)
- reverse engineering (1)
- Rootkits (1)
- Security (11)
- shellcode (1)
- Stuxnet/Duqu (2)
- Virus (1)
- Vulnerability (8)
- Web (4)
- Wifi (1)
- Windows (4)
Blog Archive
-
▼
11
(52)
-
▼
Nov
(12)
- How to Fix iOS 5 Errors
- Jailbreak iOS 5.0/iOS 5.0.1 Using Ac1dSn0w
- Anatomy of Self Inflicted Javascript Injection "fa...
- Understanding Private Clouds
- HTML5, Local Storage, and XSS
- Honey Potting for MS11-083
- Duqu Installer Contained Microsoft Word Zero-Day E...
- The History of Computer Viruses
- Memory Forensics
- Hijacking Google Analytics
- RemoteExec Computers List Buffer Overflow ROP Expl...
- Jailbreak iOS 5.0.1 On Windows Using Sn0wbreeze 2....
-
►
Jul
(11)
- Breaking MailEnable 2.34: A lesson in security fea...
- Meterpreters new reverse_http and reverse_https op...
- Capture all metasploit input/output
- Pwning Mac OS X with evilgrade + MacPorts
- reverse engineering the google +1 button-using-fir...
- Advanced Nmap
- Fiddling with Chromium's new certificate pinning
- Journey into Exploitation: awbo2.exe
- Extracting Files from a tcpdump
- How security-teams deal with leaking passwords
- Transfer Files and Data via DNS-Requests
-
►
Jun
(12)
- Passive Analysis of SSH Traffic
- DotDotPwn v2.1 - The Traversal Directory Fuzzer
- DotDotPwn - The Directory Traversal Fuzzer
- mitmproxy
- Introducing WPScan – WordPress Security Scanner
- Tomahawk, your IDS/Firewall Best Friend
- Introducing DOM Snitch, our passive in-the-browser...
- Metasploit 3.7.2 adds 11 new exploits
- IM worm targeting Brazilian Facebook users
- LulzSec Suspect Taken Into Custody
- Creating a 13 line backdoor worry free of A/V
- Searching the Registry using PowerShell
-
▼
Nov
(12)
