Microsoft offers defenses against Duqu virus

07 Nov, 2011

Microsoft on November 4 was advising companies how to defend against infection by a Stuxnet-like Duqu virus. The US technology colossus released the "workaround" along with detailed information it said would enable anti-virus software companies to detect Duqu, which takes advantage of a flaw in Windows computer operating systems.
"To make it easy for customers, we have released a fix-it that will allow one-click installation of the workaround and an easy way for enterprises to deploy," said Microsoft trustworthy computing group manager Jerry Bryant.
"Our engineering teams determined the root cause of this vulnerability, and we are working to produce a high-quality security update to address it," he said in a security advisory posted online.
A software patch to protect against Duqu will not be ready in time for this month's "update Tuesday" next week, according to Microsoft. Duqu can sneak into computers by hiding in Word document files opened as email attachments.
Duqu infections have been reported in a dozen countries including Iran, France, Britain and India, according to US computer security firm Symantec.
Symantec said the Duqu threat is growing and that slipping into machines through Word files is "one of many forms of attacks that cyber criminals can use to infect computers."
Similarities between Duqu and a malicious Stuxnet worm have prompted speculation that the same culprits might be involved, though no links have been proven.
The new virus, dubbed "Duqu" because it creates files with the file name prefix "DQ," is similar to Stuxnet but is designed to gather intelligence for future attacks on industrial control systems.
The virus takes advantage of a previously unknown vulnerability in a Windows font-parsing engine to plant malicious code in the heart of a computer system, according to Microsoft.
"An attacker who successfully exploited this vulnerability could then install programmes; view, change, or delete data; or create new accounts with full user rights," Microsoft warned in a security advisory.
"We are aware of targeted attacks that try to use the reported vulnerability; overall, we see low customer impact at this time," it said.
Stuxnet was designed to attack computer control systems made by German industrial giant Siemens and commonly used to manage water supplies, oil rigs, power plants and other critical infrastructure.
Most Stuxnet infections have been discovered in Iran, giving rise to speculation it was intended to sabotage nuclear facilities there. The worm was crafted to recognise the system it was designed to attack.

Read Comments