We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

Microsoft expected to offer hot fix for Duqu soon

The big zero-day exploit on everyone's mind is Duqu, or "son of Stuxnet" - but researchers don't expect Microsoft to include a patch for it in next week's Patch Tuesday. Instead, a manual fix could be out as soon as this week.

CHART: Duqu Malware Exploits Windows Zero-Day Kernel Bug, Attacks Via Word Document

"While many dispute the threat imposed by this bug, no one disputes the risk of the Day Zero Vulnerability in Microsoft software that it takes advantage of. The vulnerability is exploited through a malicious Word document - when the user opens the document, a Zero Day Kernel Vulnerability is taken advantage of to execute malicious code. Microsoft did not issue a patch this cycle but an advisory will likely be released today or tomorrow with a link to a 'Fix It' hot fix. This means that user intervention will be required, as a hot fix cannot be pushed out to the entire network," says Paul Henry, security and forensic analyst for patch vendor Lumension.

Duqu is worrisome because it installs a keystroke logger and then can replicate itself, even across secure networks, using the passwords obtained. It communicates with other servers across the Internet, giving hackers access. The malware will remove itself after 30 days.

The Microsoft Security team has been mostly mum on Duqu, with the exception of acknowledging the threat in a tweet Tuesday that simply said, "We are working to address a vulnerability believed to be connected to the Duqu malware."

So far it has issued no advisory. At least some of the security team have been aware of the threat for a while. On Oct. 18, Terry Zink, a program manager for Microsoft Forefront Online Security, blogged about Duqu and its possible relationship to Stuxnet

If not Duqu, Microsoft will be fixing other issues with Windows in Tuesday's crop of fixes, with four patches total, one critical, two important and one moderate. The critical patch affects all versions of Windows, client and server, including Windows Server (even Server Core).

Julie Bort is the editor of Network World's Microsoft Subnet and Open Source Subnet communities. She writes the Microsoft Update and Source Seeker blogs. Follow Bort on Twitter @Julie188.

Read more about wide area network in Network World's Wide Area Network section.


IDG UK Sites

Microsoft Band UK release date and price rumours, features and specs: Microsoft smartwatch unveiled

IDG UK Sites

Why Sony's PS4 2.0 update is every gamer's dream (well, mine at least)

IDG UK Sites

This Grolsch ad combines stop-motion & CG for majestic results

IDG UK Sites

Apple rumours and predictions for 2015: What to expect from Apple in 2015