Posts Tagged 2286198
Security: MS Security Advisory 2286198 (Zero-day)
Posted by Lars Krogh in Hints on 22/07/2010
The lastest zero-day Windows vulnerability (All versions) can be exploited locally through a malicious USB drive, or remotely via network shares and WebDAV.
Chester Wisniewski’s Blog (working at Sophos) describes the use of a GPO to protect you against the exploit. The GPO should disallow the use of executable files that are not on the C: drive. If you need to run executable files from a network drive (old programs?) just specify the specific network paths in the GPO.
The exploit in action
