No Patch for Critical Duqu 0-Day Vulnerability in Windows Next Week

Status
Not open for further replies.

jamescv7

Level 85
Thread author
Verified
Honorary Member
Mar 15, 2011
13,070
Microsoft plans to release four security bulletins next week as a part of its monthly patch cycle, but an update designed to fix the critical zero-day vulnerability exploited by the Duqu malware won’t be among them.

Jerry Bryant, group manager, Response Communications Trustworthy Computing Group, confirmed this detail officially, while stressing that the software giant is indeed hard at work on a patch.

Bryant notes that the level of risk to which customers running Windows are exposed because of the Duqu malware attacks is low.

“Our engineering teams determined the root cause of this vulnerability, and we are working to produce a high-quality security update to address it. At this time, we plan to release the security update through our security bulletin process, although it will not be ready for this month’s bulletin release,” Bryant said.

For the time being, attackers are spreading Duqu through social engineering tactics designed to convince unsuspecting users to open malformed Word documents served as email attachments.

Read More
 

McLovin

Level 76
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,224
Maybe not punch him, but we might have to write him a very juicy email to release it.
 
D

Deleted member 178

he dont want release a fix because he created the evil (Count) Duqu :p you must relies on the Jedis
 

moonshine

Level 7
Verified
Apr 19, 2011
1,264
That's just disappointing. Although I have expected from the start that this is gonna happen sooner.
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
1. Don't open unknown email attachments.
2. Your AV should detect it. (?)
 

Hungry Man

New Member
Jul 21, 2011
669
Patches are nice but not a big deal. We live in a world where we can't rely on them nor should we try.
 

moonshine

Level 7
Verified
Apr 19, 2011
1,264
Patches usually comes in too late enough that most users are already compromised. :p
 

jamescv7

Level 85
Thread author
Verified
Honorary Member
Mar 15, 2011
13,070
Well since there is no patch for next week, then they must take precautionary measures and likely said by Earth that's exactly needed.
 

PenTester

New Member
Jul 30, 2011
114
Duqu is spotted as "Stars" spyware that attacked Iran's Nuclear programs in april 2011. Kaspersky updated software that will detect Duqu Trojan.

Malware Report
 

PenTester

New Member
Jul 30, 2011
114
Crysys Lab developed Duqu detection tool.

Download it from here:
http://www.crysys.hu/duqudetector-files/files/duqudetector-v1_01.zip

Manual:
http://www.crysys.hu/duqudetector-files/files/manual-v1_01.txt
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top