Critical bug in 40 Windows apps!
Posted: 23 Aug 2010, 19:36
A “binary planting” vulnerability in Apple iTunes for Windows allows local or remote (even Internet-based) attackers to deploy and execute malicious code on Windows machines in the context of logged-on users.
Since Windows systems by default have the Web Client service running - which makes remote network shares accessible via WebDAV -, the malicious DLL can also be deployed from an Internet-based network share as long as the intermediate firewalls allow outbound HTTP traffic to the Internet.
A systematic attack could deploy malicious code to a large number of Windows workstations in a short period of time, possibly as an Internet worm.
Now you know
|
Critical bug in 40 apps |
Since Windows systems by default have the Web Client service running - which makes remote network shares accessible via WebDAV -, the malicious DLL can also be deployed from an Internet-based network share as long as the intermediate firewalls allow outbound HTTP traffic to the Internet.
A systematic attack could deploy malicious code to a large number of Windows workstations in a short period of time, possibly as an Internet worm.
Now you know