Thursday, July 22, 2010

Microsoft Advisory 2286198: Windows Shell RCE

We have implemented the following network filters to protect users because of Microsoft Advisory 2286198: Windows Shell RCE

10030: HTTP: Microsoft Shell Link Binary File Download
10031: SMTP: Microsoft Shell Link Binary File Attachment
2461: SMTP: Zip Attachment Containing .pif File
2463: POP/IMAP: Zip Attachment Containing .pif File
2711: SMTP: Rar Attachment Containing .pif File
2713: POP/IMAP: Rar Attachment Containing .pif File

We are also looking into implementing the following filter but because of the placement of the filters we need to do more testing before enabling it.

10034: SMB: Microsoft Shell Link Binary File Transmission

If you have any questions or problems please notify the Region 18 ESC Helpdesk at 432.561.4321 or by email helpdesk@esc18.net

Thanks,
Region 18 ESC Network Operations Center