Back on track as for one of our favorite rant subjects: desktop security.
This stuff,
commonly called the “LNK vulnerability”, has gained quite some momentum in the
last days, including the release of
a Metasploit module
and a temporary raise of SANS Internet Storm Center‘s
Infocon level to yellow (it’s back on green in the interim).
CVE-2010-2568 has been assigned and some technical details can be found
here
and here.
To give you a rough idea how this piece works, here’s a quote from the
US-CERT advisory:
This is the first post of a – potential – series of rants on ubiquitous pieces
of crap (security-wise), bothering pretty much every ISO I know.
I’m talking about “common desktop applications” and today’s topic is going to be
the beloved Adobe Flash Player. Some of you who had the opportunity (or
imposition 😉 to listen to one my talks covering “modern enterprise security
space” (e.g.
this one)
might remember me saying sth like “If a fairy godmother turned up and asked me
for three things to get rid of in order to enhance overall corporate information
security in a sustainable way, my answers would be…” and then giving Adobe Flash
as the first mention. (before you ask: amongst the other candidates are Apple
Quicktime, Windows GDI and “Javascript in Acrobat Reader”).