Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More
Access immediate incident response support, available 24/7
The vulnerability described in Microsoft Security Advisory 2269637, involves using a legitimate application to preload malicious library files from remote sources, including SMB shares and WebDAV. For example, an audio/video player application might be tricked into loading malware that poses as a codec DLL. This technique is sometimes called “DLL hijacking”. Although SMB falls outside of the scope of secure web gateway solutions, SWG appliances can prevent client applications from using WebDAV to retrieve malicious libraries from the Internet. By default, SWG appliances include a rule named Block Binary Objects without a Digital Certificate. Since malware authors do not sign their code, this rule by itself blocks exploits based on this vulnerability. In some environments, it is preferable to permit downloading of unsigned binaries, so the Block Binary Objects without a Digital Certificate rule is sometimes disabled or placed in X-Ray mode. In this situation, it is still possible to define a policy that prevents attempts to exploit this vulnerability via WebDAV. Doing so involves preventing WebDAV downloads of .dll and .ocx files. The procedure for creating the appropriate lists and rule is detailed below.
To contact LevelBlue about this article or to request support: