<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Patch</title><link>http://pandalabs.pandasecurity.com/archive/tags/Patch/default.aspx</link><description>Tags: Patch</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>MS09-002 Exploit in the Wild</title><link>http://pandalabs.pandasecurity.com/archive/MS09_2D00_002-Exploit-in-the-wild.aspx</link><pubDate>Thu, 19 Feb 2009 03:34:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:967</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/967.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=967</wfw:commentRss><description>&lt;p&gt;Last Tuesday Microsoft released a Security Bulletin (&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS09-002.mspx"&gt;MS09-002&lt;/a&gt;) for critical vulnerabilities which affected its Internet Explorer browser.  The vulnerability exists because of improper error handling when accessing deleted objects and allows remote code execution through a specially crafted website.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Exploit Code" height="394" src="http://support.us.pandasecurity.com/blog/MS09-Exploit.jpg" width="696" /&gt;&lt;/p&gt;
&lt;p&gt;This week a few websites in China started to actively exploit this vulnerability and the malware (jc.exe &amp;amp; wininet.dll) is detected as Spyware/Virtumonde.  The websites involved in this example have been blocked by Panda&amp;rsquo;s Identity Protect Technology, which will block Panda&amp;#39;s users before reaching the exploit sites.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp; We recommend applying Microsoft&amp;#39;s &lt;a href="http://www.microsoft.com/technet/security/bulletin/MS09-002.mspx"&gt;patch&lt;/a&gt; immediately.&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=967" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Exploit/default.aspx">Exploit</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Patch/default.aspx">Patch</category></item></channel></rss>