CyberInsecure.com

Daily cyber threats and internet security news: network security, online safety and latest security alerts
August 2nd, 2010

Microsoft Rushes Out Emergency Fix For Critical LNK Bug

Microsoft on Monday rushed out an emergency patch for a critical vulnerability that criminals are exploiting to install malware on all supported versions of the Windows operating system.

As promised Friday, Microsoft released the update outside of its normal patching schedule because the vulnerability is being actively targeted. When the flaw first came to public attention three weeks ago, it was being used to attack SCADA — supervisory control and data acquisition — systems that control sensitive equipment at power plants, gas refineries, and other other critical infrastructure.

Since then, it’s been used to install general-purpose malware from Zeus and other do-it-yourself crimeware kits used to siphon credit card numbers and other sensitive data from compromised computers. The Windows flaw resides in a shortcut feature that makes it easy to store commonly accessed files and folders on the operating-system desktop.

Users who employed a stopgap FixIt published two weeks ago should roll back their machines using the “disable workaround” feature here. Those who don’t follow this advice will find that icons fail to display properly, causing folders and files to appear white without any of the customary graphics.

Users will most likely have to reboot their machines twice — once after uninstalling the workaround, and again after installing the update.

Credit: The Register

Share this item with others:

More on CyberInsecure:
  • Microsoft, Adobe, Apple Fix Critical Security Vulnerabilities
  • Windows .lnk Shortcut Zero-Day Critical Vulnerability Confirmed By Microsoft
  • Microsoft Releases Emergency Patch For Critical Windows Vulnerability
  • Critical Internet Explorer Security Vulnerability Fixed By Microsoft
  • Record Number Of Vulnerabilities Fixed In Microsoft’s Patch Tuesday

  • If you found this information useful, consider linking to it from your own website.
    Just copy and paste the code below into your website (Ctrl+C to copy)
    It will look like this: Microsoft Rushes Out Emergency Fix For Critical LNK Bug

    Leave a Reply

    Comments with unsolicited links to other resources will be marked as spam. DO NOT leave links in comments. Please leave your real email, it wont be published.

    *
    To prove you’re a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.