Google Engineer Exposes Microsoft Windows Bug

Microsoft issued a security advisory June 10 after a Google engineer published attack code targeting a Windows zero-day vulnerability on the Full Disclosure message list.

The vulnerability, uncovered by Google engineer Tavis Ormandy, affects “the Windows Help and Support Center function that is delivered with Windows XP and Windows Server 2003,” Microsoft said. Other editions of the operating system are not impacted by the bug.

“Launching the Help and Support Center via an hcp:// link is normally safe and is a supported way to launch help content,” said a post on Microsoft’s Security Research & Defense blog. “This is due in part to an ‘allow list’ of safe pages that Help and Support Center checks before navigating to a passed-in page. The Google security researcher found a help page with a cross-site scripting vulnerability and also a mechanism by which to abuse the allow list functionality to access that page with an exploit querystring. Clicking on a malicious hcp:// link leverages the XSS vulnerability to circumvent helpctr.exe’s safety controls and ultimately run an arbitrary .exe installed on the machine.”

Attacks may be forthcoming

So far, Microsoft has not seen any evidence the vulnerability is being targeted in the wild. However, attacks may be forthcoming since Ormandy’s code is public.

In his Full Disclosure message, Ormandy wrote that he reported the bug to Microsoft on 5 June. His decision to publish proof-of-concept attack code and details of the bug on the web has sparked some criticism from security professionals.

Andrew Storms, director of security operations at nCircle, described Ormandy’s actions as “effectively forcing Microsoft’s hand. He used the same process on another bug he discovered earlier this year … you have to wonder if he is adding fuel to the very public fire between Microsoft and Google by continuing to draw negative attention to Microsoft’s security process.”

Google and Microsoft have engaged in some verbal sparring lately, starting with media reports that Google is dumping Windows in favour of other operating systems, in part due to security concerns. Microsoft countered with a blog post detailing some of the security features of Windows and pointing to examples of malware targeting Mac computers as well as to Yale University’s decision to halt its move to Google Gmail for security reasons.

Patch and workarounds

Microsoft said in the advisory that it is working on a patch. In the meantime, there are some workarounds given in the advisory that could help.

“The full-disclosure advisory included a hotfix tool built by the Google security researcher,” said the Microsoft Security Research & Defense blog post. “Unfortunately, it is ineffective at preventing the vulnerable code from being reached and can be easily bypassed. We recommend not counting on the Google hotfix tool for protection from the issue. The best workaround is to unregister the hcp:// protocol handler. Doing so will prevent the chain of events that leads to the code execution.”

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Apple, Google Mobile Ecosystems Should Be Investigated, CMA Told

CMA receives 'provisional recommendation' from independent inquiry that Apple,Google mobile ecosystem needs investigation

5 hours ago

Australia Rejects Elon Musk Claim About Social Media Ban For Under-16s

Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…

8 hours ago

Northvolt Files For Bankruptcy Protection In US

Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…

10 hours ago

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

1 day ago

Former Policy Boss At X, Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

1 day ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

1 day ago