|
|
While the latest CommWarrior variants continues to entice mobile phone users into clicking "Yes" to grant it permission to install, Collin Mulliner published the first remote exploit for Windows Mobile phones using MMS as the attack vector, at the Defcon 14 conference in Las Vegas.
The vulnerabilities in question will only require the Windows Mobile 2003 (Windows CE 4.2) user to open a malformed MMS message to cause a buffer overflow in the Sychronized Multimedia Integration Language (SMIL) parser. When successful, the exploit can execute code on the targeted mobile phone to silently install malware. The "success rate" of the exploit varies, as according to Collin, the return address, like a "key" to execute malicious code is random and can vary across mobile phone makes and models. This makes it less likely a worm candidate.
|
|
Tags: malware
Defcon 14 was in 2006 and you website doesn’t list a CommWarrior on it’s recent threats page. If this entry is topical, it’s not clear to me. And if historical, I’m missing that significance too.
Submit your own comments / message for this post