Software flaw that allowed Stuxnet virus to spread was the most exploited in 2016
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2010-2568 | Remote Code Execution in Microsoft Windows via Malicious Shortcut (LNK) Parsing CVE-2010-2568 is an input-validation flaw (CWE-20) in how Microsoft Windows parses shortcut files, allowing malicious code to execute when the operating system merely displays the icon of a malicious shortcut (.lnk) file. Triggering requires nothing more than the Windows shell rendering the shortcut's icon — for example when browsing a folder containing the file, a vector widely abused via USB drives and network shares in incidents tied to Stuxnet and Gauss. A successful attacker gains arbitrary code execution with the privileges of the logged-on user, suitable for initial access or lateral movement. All Microsoft Windows systems as listed by CISA are affected; the provided data does not specify exact version ranges. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2022-09-15), carries a 91.3% EPSS probability of exploitation (100th percentile), and related headlines report Microsoft having to re-issue the fix more than once for Stuxnet-related attacks. Do: Apply Microsoft updates per vendor instructions (CISA's required action); since headlines indicate this LNK fix was re-released multiple times, verify systems carry the latest cumulative Windows updates rather than only the original patch. Until patched, avoid browsing untrusted removable drives or network shares with a shell that renders shortcut icons, and monitor for LNK-delivered malware. | — | 91% | KEV |
| mass≈1 billion+ Windows installations worldwide (unknown share unpatched; legacy versions carry the highest risk) |
Full article722 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Software updates aren’t the cybersecurity silver bullet that some computer experts make them out to be.
Software updates might strengthen cybersecurity, but they’re hardly the full picture when it comes to digital hygiene.
One of the most famous Windows vulnerabilities in history — a coding flaw that was originally discovered in 2010 and had a role in the elaborate U.S. intelligence mission to handicap Iran’s nuclear enrichment program — was the most widely exploited software bug in both 2015 and 2016, according to new research by antivirus provider Kaspersky Lab, even though Microsoft rolled out a patch in August 2010.
“The life of an exploit doesn’t end with the release of a security patch designed to fix the vulnerability being exploited,” Kaspersky Lab researchers wrote in a blog post Thursday sourcing proprietary and open-source intelligence reports. “Once made public, a vulnerability can become even more dangerous: grabbed and repurposed by big threat actors within hours.”
Kaspersky Lab found that 27 percent of its user base had at one point encountered the “CVE-2010-2568” Microsoft exploit between 2015 and 2016. The Moscow-based cybersecurity firm qualified its finding by framing the results as the percentage “of users who encountered a particular exploit threat out of all those who encountered any malware categorized as an exploit.”
(The current Wikipedia definition of an exploit is as good as any: “a piece of software, a chunk of data, or a sequence of commands that takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur in computer software, hardware or something electronic.”)
Indexed as CVE-2010-2568 by Microsoft, the exploit targets a code execution vulnerability that can be triggered by plugging a malware-laden USB stick into a computer that’s running an unpatched older version of Microsoft Windows, including Vista and XP.
More specifically, the bug allows for an attacker to hide malicious code inside .LNK files even when a machine’s auto-run feature is turned off — LNK files are used by the operating system to display graphical icons whenever an external hard drive is inserted into a computer’s USB port.
CVE-2010-2568 remains prominent on the list of exploited bugs in part because it allows a computer virus to spread without an internet connection. Attacks that leverage the vulnerability require little interaction on the part of the hacker beyond an original physical point of access. If an infected computer resides inside a shared network then the exploit will quickly spread to all of the neighboring, vulnerable machines.
First reported by the New York Times’ David Sanger, CVE-2010-2568 links back to a secretive and powerful Stuxnet cyber-weapon developed by the U.S. to disrupt electronic hardware inside Iranian enrichment facilities. The contagious computer worm virus quickly spread outside of Iran and it has since been recycled and re-weaponized by various hackers.
Security researchers believe that the Equation Group, an elite hacking team linked to the NSA, was the first to exploit the .LNK vulnerability in 2008. In that case, the group used a combination of multiple zero-day exploits and the .LNK vulnerability to spread a worm dubbed Fanny.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/software-flaw-allowed-stuxnet-virus-spread-exploited-2016/