Microsoft ActiveX Snapshot Viewer for Microsoft Access RCE

Notification Type: IBM Internet Security Systems Protection Alert
Notification Date: July 7, 2008
Notification Version: 1.3
   
Name: Microsoft ActiveX Snapshot Viewer for Microsoft Access RCE
Public disclosure/
In the wild date:
July 7, 2008 (vuln disclosure)
Aliases:

Microsoft Security Advisory (955179)

CVE:

CVE-2008-2463

Description: Microsoft ActiveX Snapshot Viewer for Microsoft Access could allow a remote attacker to execute arbitrary code on the system.  Targeted exploitation was reported on July 7, but X-Force has been monitoring toolkit-related mass exploitation since July 10.  As of July 24, exploitation has continued to escalate.  See technical description for more details.

 

ISS Coverage

Product Content Version
Proventia Network IDS
Proventia Network IPS
Proventia Network MFS
Proventia Server (Linux)
RealSecure Network
RealSecure Server Sensor
varies, see ISS Protection below
Proventia Desktop
Proventia Server IPS (Windows)
varies, see ISS Protection below
Propagation Techniques ISS Protection Available

remote exploit


related malware

HTML_Access_Snapshot_Viewer_ActiveX
HTML_IE_ActiveX_Loader_Heap_Corruption*

Mal/Behav-058 (Proventia Multifunction)
Generic.Graybird.5ECCEB5C (Proventia Desktop)

July 9, 2008
July 12, 2005

late 2006
Jan 30, 2007

* HTML_IE_ActiveX_Loader_Heap_Corruption can be customized with a tuning parameter to block the affected ActiveX control by identifying the "killbit" and blocking it.  To tune your policy to block this ActiveX control, create an entry using the pam.content.clsid.activexloaderbo.blacklist parameter for every killbit associated with this issue (listed in the Microsoft Advisory).

Example:

pam.content.clsid.activexloaderbo.blacklist = F0E42D50-368C-11D0-AD81-00A0C90DC8D9 

Detailed Description

Business Impact:

Microsoft ActiveX Snapshot Viewer for Microsoft Access is installed by default with multiple versions of Microsoft Office Access.  However, this ActiveX control could also be pushed down to the browser by a determined attacker if the ActiveX control is not already installed.  Therefore, this vulnerability is applicable to Microsoft Internet Explorer users in general that have administrator privileges.

Compromise of machines may lead to exposure of confidential information, loss of productivity, and further compromise. An attacker would need to entice a user to click a link to trigger this vulnerability.

CVSS Base Score: 9.3
  Access Vector: Network
Access Complexity: Medium
Authentication: None
Confidentiality Impact: Complete
Integrity Impact: Complete
Availability Impact: Complete
Adjusted Temporal Score: 9.3
  Exploitability: High
Remediation Level: Workaround
Report Confidence: Confirmed
Affected Products: For a full list of affected versions, see references below.
Technical Description:

Microsoft Windows ActiveX Snapshot Viewer for Microsoft Access could allow a remote attacker to download files to any location on an end-user's computer, including the start-up directory, which would result in arbitrary code execution. By persuading a victim with administrative privileges to click a link, a remote attacker could exploit this vulnerability to execute arbitrary code on the system.

IBM Managed Security Services (MSS) has observed active, toolkit-related exploitation of this vulnerability.  At least one toolkit, Neosploit, has been updated with an exploit for this vulnerability, and MSS has been monitoring escalating exploitation attempts possibly related to Chinese attackers. These in-the-wild exploits have been known to drop variants of the Hupigon backdoor that is caught by many antivirus vendors.  As of July 24, over 50 unique servers have been seen exploiting this vulnerability.

Remediation:

Patches were not available for this issue at the time of publication. See References for updates on patch availability.

In addition to IPS and antivirus protection, administrators should consider disabling this ActiveX control in all web browsers of systems that are under their control.  Most exploit toolkits like the toolkit using an exploit for this vulnerability have been known to employ obfuscation, which may make some IPS blind to the attack.  For more information on disabling this ActiveX control, see the Microsoft Advisory.

References

XFDB: http://xforce.iss.net/xforce/xfdb/43613
Microsoft: http://www.microsoft.com/technet/security/advisory/955179.mspx

Revision History

1.0 Initial publication.
1.1 Updated signature name and CVSS score.
1.2 Added information about active exploitation and upgraded CVSS temporal score.
1.3 Added additional information about continued exploitation.


About IBM Internet Security Systems
IBM Internet Security Systems is the trusted security advisor to thousands of the world's leading businesses and governments, providing pre-emptive protection for networks, desktops and servers. An established leader in security since 1994, the IBM Proventia® integrated security platform is designed to automatically protect against both known and unknown threats, helping to keep networks up and running and shielding customers from online attacks before they impact business assets. IBM Internet Security Systems products and services are based on the proactive security intelligence of its X-Force® research and development team – the unequivocal world authority in vulnerability and threat research. The Internet Security Systems product line is also complemented by comprehensive Managed Security Services and Professional Security Services. For more information, visit the Internet Security Systems Web site at www.iss.net or call 800-776-2362.