Microsoft has released a quickly crafted patch to combat a severe zero-day vulnerability discovered only days ago.
Late Monday, the Redmond giant issued a security advisory for CVE-2017-0290, a remote-code execution flaw affecting its Windows operating system.
The vulnerability was disclosed over the weekend by Google Project Zero security experts Natalie Silvanovich and Tavis Ormandy.
On Twitter, prominent vulnerability hunter Ormandy revealed the existence of a zero-day flaw in Microsoft Malware Protection Engine (MsMpEng), used by Windows Defender and other security products.
The researcher tweeted that he and Silvanovich had "discovered the worst Windows remote code exec in recent memory. This is crazy bad."
Ormandy did not reveal anything else, giving Microsoft time to fix the scripting engine memory corruption vulnerability after they reported it privately. The built-in deployment system and scanner engine in Microsoft's products will issue the patch automatically over the next 48 hours, so more details have been disclosed.
The vulnerability allows attackers to remotely execute code if the Microsoft Malware Protection Engine scans a specially crafted file. When successfully exploited, attackers are able to worm their way into the LocalSystem account and hijack an entire system.
With such power, they have complete control to install or delete programs, steal information, create new accounts with full user rights and download additional malware.
Google's Project Zero team said the vulnerability can be leveraged against victims by simply sending an email to users -- without the need for the message to be opened or any attachments to be downloaded. An attack leveraging the exploit could also be conducted through malicious website visits or instant messaging.
According to Ormandy, the vulnerability could not only be exploited to work against default systems, but is also "wormable." In other words, malware using the exploit can replicate itself and spread beyond the target system.
"Vulnerabilities in MsMpEng are among the most severe possible in Windows, due to the privilege, accessibility, and ubiquity of the service," the team said.
Microsoft acknowledged the severity. "If the affected antimalware software has real-time protection turned on, the Microsoft Malware Protection Engine will scan files automatically, leading to exploitation of the vulnerability when the specially crafted file [is] scanned," Microsoft said. "If real-time scanning is not enabled, the attacker would need to wait until a scheduled scan occurs in order for the vulnerability to be exploited."
Microsoft Builds Emergency Patch for Severe Windows Bug

Microsoft has released a quickly crafted patch to combat a severe zero-day vulnerability discovered only days ago. Late Monday, the Redmond giant issued a security advisory for CVE-2017-0290, a…
Comms Week
Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

Google Issues Urgent Chrome Update to Block Active Attacks

RockPay Launches, Targets Digital Payments through Social Finance

NDIC Still Paying Depositors of 46 Failed MFBs — Sunday

NITDA Inaugurates Taskforce to Drive Sovereign Cloud Implementation

SEC Proposes N2bn Capital Requirement, N30m Registration Fee for Crypto Firms




