News  

Sophos Launches tool for Windows Zero-Day Vulnerability

PC World Team 27 Jul 2010
Internet_1

Sophos has released a free tool to protect against Windows zero-day vulnerability, which has been targeted by malware writers to infect computers. Sophos says that the Sophos Windows Shortcut Exploit Protection Tool protects against a high profile vulnerability that allows malicious hackers to exploit a bug in the way that all versions of Windows handles .LNK shortcut files. If Windows just displays the icon of an exploited shortcut file, malicious code can be executed - without requiring any interaction by the user.

"So far we have seen the Stuxnet and Dulkis worms, as well as the Chymin Trojan horse, exploiting the shortcut vulnerability to help them spread and infect computer systems.  Stuxnet made the headlines because it targeted the Siemens SCADA systems that look after critical infrastructure like power plants - but there's a warning for all computer users here. Details of how to exploit the security hole are now published on the web, meaning it is child's play for other hackers to take advantage and create attacks." said Graham Cluley, Senior Technology Consultant at Sophos.

The Sophos Windows Shortcut Exploit Protection Tool intercepts shortcut files that contain the exploit, warning of the executable code that was attempting to run. That means it will stop malicious threats which use the vulnerability if they are on non-local disks, such as a USB stick.

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Enter the characters shown in the image.

Spammers Publishing Rogue Apps On Android Market

Spammers are impersonating well-known ..

Nokia Belle Update for Symbian ^3/Anna Users Available Now

The phones receiving this update inclu..

All News