• Critical Vulnerability and Privacy LoopHole Found in RoboForm Password Manager

    Unless you are a human supercomputer, remembering password is not so easy, and that too if you have a different password for each site. But luckily...
  • miniLock - Open Source File Encryption Tool from CryptoCat Developer

    It’s the age of surveillance what made the Use of Encryption so widely that it has become a need of law enforcement agencies, cyber criminals as...
  • A BEGINNERS GUIDE TO HACKING UNIX

      *************  *       A BEGINNERS GUIDE TO:        *  *        ...
  • CASH! CASH! Hacking ATM Machines with Just a Text Message

    As we reported earlier, Microsoft will stop supporting the Windows XP operating system after 8th April, apparently 95% of the world’s 3 million...
  • Microsoft Word Zero-Day Vulnerability is being exploited in the Wild

    Microsoft warned about a zero-day vulnerability in Microsoft Word that is being actively exploited in targeted attacks and discovered by the...
  • Snoopy Drone Can Hack Your Smartphones

    The use of unmanned aerial vehicles (UAVS) called Drones is rapidly transforming the way we go to war. Drones were once used for...
  • Android Privilege Escalation Flaws leave Billions of Devices vulnerable to Malware Infection

    Android - a widely used Smartphone platform offered by Google is once again suspected to affect its users with malicious software that puts...
  • Introduction to Netcat

    Introduction : So I was messing around on the internet and came across a tool called Netcat.  I've been messing with it for a couple of...
  • Google Nexus phone vulnerable to SMS-based DOS attack

    Google’s Nexus Smartphones are vulnerable to SMS-based DOS attack, where an attacker can force it to restart, freeze, or lose network...
  • Linux worm targeting Routers, Set-top boxes and Security Cameras with PHP-CGI Vulnerability

    A Symantec researcher has discovered a new Linux worm, targeting machine-to-machine devices, and exploits a PHP vulnerability...

Sunday, 17 November 2013

Japanese word processor 'Ichitaro' zero-day attack discovered in the wild .

Japanese most popular word processing software 'Ichitaro' and Multiple Products are vulnerable to a zero day Remote Code Execution Flaw Vulnerability, allowing the execution of arbitrary code to compromise a user's system.

According to assigned CVE-2013-5990malicious attacker is able to gain system access and execute arbitrary code with the privileges of a local user.
The vulnerability is caused due to an unspecified error when handling certain document files. "We confirm the existence of vulnerabilities in some of our products." company blog says.

In a blog post, Antivirus Firm Symantec confirmed that in September 2013, they have discovered attacks in the wild attempting to exploit this vulnerability during, detected as Trojan.Mdropper, which is a variant of Backdoor.Vidgrab.

Researchers mentioned that Backdoor.Vidgrab variant was used as a payload for a watering hole attack exploiting the Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2013-3893), which was patched in October 2013.



According to them, it is reasonable to assume that the same malware group, or another group with close connections, is behind the attacks that utilized the Internet Explorer and Ichitaro vulnerabilities.
"Backdoor.Vidgrab is known to be used to target the Asia-Pacific region with government sectors being the primary targets."
Vulnerable products:
  • JustSystems Ichitaro 2010
  • JustSystems Ichitaro 2011
  • JustSystems Ichitaro 2011 Sou
  • JustSystems Ichitaro 2012 Shou
  • JustSystems Ichitaro 2013 Gen
  • JustSystems Ichitaro 2013 Gen Trial
  • JustSystems Ichitaro Government 2009
  • JustSystems Ichitaro Government 2010
  • JustSystems Ichitaro Government 6
  • JustSystems Ichitaro Government 7
  • JustSystems Ichitaro Government 2006
  • JustSystems Ichitaro Government 2007
  • JustSystems Ichitaro Government 2008
  • JustSystems Ichitaro Portable with oreplug
  • JustSystems Ichitaro Pro
  • JustSystems Ichitaro Pro 2 Trial
  • JustSystems Ichitaro Pro 2
  • JustSystems Ichitaro Viewer
Attackers are distributing malware with spear phishing attack, as email attachments with the Ichitaro file extension .jtd, the files are actually .rtf or rich text format files. The files cannot be opened using Microsoft Word as they are designed to work only with Ichitaro.
"The attackers, possibly belonging to the APT12 group who may have also developed BackdoorVidgrab, are persistently targeting similar, if not the identical, targets by attempting to exploit Ichitaro." Symantec says.
A patch is available from the Ichitaro Web site  to fix the vulnerability on the relevant products.

No comments:

Post a Comment