LandzDown Forum

Security => Security Alerts & Briefings => Topic started by: Corrine on November 04, 2011, 07:41:16 PM

Title: Security Advisory 2639658 and Microsoft Fix it (Duqu Trojan)
Post by: Corrine on November 04, 2011, 07:41:16 PM
Security Advisory 2639658 (http://technet.microsoft.com/en-us/security/advisory/2639658) relates to a Windows kernel issue related to the Duqu malware, a trojan that injects malicious code into other processes.  An update is not expected to be ready for delivery with the scheduled November update.  A Microsoft Fix it solution is available from Microsoft KB Article 2639658 (http://support.microsoft.com/kb/2639658).

Additional details are available in my article at Microsoft Fix it for Duqu Malware, Security Advisory 2639658 (http://securitygarden.blogspot.com/2011/11/microsoft-fix-it-for-duqu-malware.html).




Title: Re: Security Advisory 2639658 and Microsoft Fix it (Duqu Trojan)
Post by: Corrine on November 06, 2011, 11:39:50 PM
After enabling Microsoft Fix it 50792, there have been reports of Microsoft updates KB 972270 (MS10-001: Vulnerability in the Embedded OpenType Font Engine could allow remote code execution (http://support.microsoft.com/kb/972270)) and KB 982132 (MS10-076: Vulnerability in the Embedded OpenType Font Engine could allow remote code execution (http://support.microsoft.com/kb/982132)) being repeatedly re-offered.

In the event you experience the same issue, after confirming in the update history that both updates are installed, I suggest that you enable the Fix it and then hide the updates when offered again.

To hide the updates, select the first update and then right-click the update and click "Hide Update." Repeat for the second update.