Earlier today, we encountered a malware that exploits a recently (and publicly) disclosed vulnerability, the MIDI Remote Code Execution Vulnerability (CVE-2012-0003).
The said vulnerability is triggered when Windows Multimedia Library in Windows Media Player (WMP) fails to handle a specially crafted MIDI file, consequently allowing remote attackers to execute arbitrary code.
Meanwhile, as the routines stated above happens in the background, the affected users remains unsuspecting and sees the following:
On the other hand, Trend Micro customers are already protected from this by Smart Protection Network, which blocks the related malicious files and URLs.
We will update this blog entry once more information is available.
Leave a reply