Ramblings of an old Doc

 

 

It is very important to get this emergency patch since Flame masquerades as an MS update. 


(Photocredit gHacks)

“Flame” is a virus/Trojan which was designed to collect information through up to 20 modules. It was designed to collect information on the Middle East and on Iranian-Russian nuclear reactors. It probably also has other intelligence gathering and possibly operational options in it.

It exploits a vulnerability in MS software, specifically its security certificate signing, it appears. It makes the malware appear as if it’s MS original software and then hides.

For that reason, MS has issued an emergency patch. There are also tools to discover and fix any Flame.A and/or Flame.B infection.

So… why should you be interested? Simply because once one of these things is released, they can “evolve” to exploit other holes and do other things, just like biological creatures in the wild evolve.

Plugging this hole may not protect you from others, but it doesn’t accomplish much to worry about plugging other possible holes while not attending to the one which already exists… and which will be exploited.

 

Source:

http://www.ghacks.net/2012/06/04/windows-security-emergency-patch-to-fix-flame-loophole/?_m=3n%2e0038%2e541%2ehj0ao01hy5%2ejw4

http://www.techrepublic.com/blog/window-on-windows/special-patch-alert-flame-malware-targets-microsoft-update/6225?tag=nl.e064


Comments
on Jun 05, 2012

Update:

Looks like it might have happened already.

While it's possible this was part of the "original", it could be adaptation of Flame by cyber criminals.

Source: http://www.infopackets.com/news/business/microsoft/2012/20120605_hackers_fake_microsoft_update_spread_malware.htm

on Jun 05, 2012

I got the patch yesterday. 

on Jun 05, 2012

Update one of one? I didn't check it out.

KB2718704 is the one I got yesterday.

on Jun 06, 2012

It is very important to get this emergency patch since Flame masquerades as an MS update. 


http://www.techrepublic.com/blog/window-on-windows/special-patch-alert-flame-malware-targets-microsoft-update/6225?tag=nl.e064