USB malware flaw hits Windows
By Nicole Kobie
Posted on 19 Jul 2010 at 09:11
A new type of malware is targeting Microsoft operating systems via infected USB drives.
The newly discovered Stuxnet malware uses a flaw in Windows to infect PCs using shortcut icons, Microsoft said.
"The vulnerability exists because Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the user clicks the displayed icon of a specially crafted shortcut," Microsoft said in a security warning. "This vulnerability is most likely to be exploited through removable drives."
"Currently, we have seen only limited, targeted attacks on this vulnerability," Microsoft added, but said it expects other malware writers to start using the USB shortcut flaw too.
Security firm Trend Micro agreed. "Despite the numerous potential techniques for proliferation being offered by the web, USB malware continue to be distributed by cybercriminals, which only proves their effectiveness," JM Hipolito wrote on the Trend Micro blog.
The flaw affects Windows OSes from XP to 7, as well as Server 2003 and 2008. Microsoft has issued a pair of workarounds, advising users to disable the icon for shortcuts or the WebClient service, which it sees as the "most likely remote attack vector."
Is your business a social business? For helpful info and tips visit our hub.
- Hello Cortana, it's nice to meet you
- Windows 8.1 Update: an abject surrender
- The insane economics of Sky Now TV
- No such thing as a free app... so pay up if you want quality
- Time to outlaw crapware-laden installers
- Windows Phone 8.1 video: hands-on
- Office for iPad: key information
- Why every PC buyer owes Richard Durkin a debt of gratitude
- HTC One M8 vs Samsung Galaxy S5: 2014's big-hitters compared
- Windows XP end of life: key information
- How to write your company's IT security policy
- The key to choosing a secure password
- Please stop reposting fake Facebook messages
- Is Facebook safe for business?
- Don't rely on Chrome's password vault
- Facebook Graph Search: don't panic
- Gmail drafts and Pastebin: could they evade the email snoops?
- Applying for a job at GCHQ? Here's your plain-text password
- Google two-step verification: a must for business email
- Yes, I write down my passwords