Free Windows Shortcut Exploit Protection Tool From SOPHOS
July 27, 2010 by admin
Filed under Protection Tools
What is the Windows Shortcut Exploit?
The Windows Shortcut Exploit, also known as CPLINK, is a zero-day vulnerability in all versions of Windows that allows a Windows shortcut link, known as an .lnk file, to run a malicious DLL file. The dangerous shortcut links can also be embedded on a website or hidden within documents.
The exploit works when you open a device, network share or WebDav point carrying an infection—you don’t need to click on anything for the exploit to work, even if you have AutoPlay and AutoRun disabled.
SophosLabs first saw this exploit at work through the rootkit W32/Stuxnet-B, which targets Siemens SCADA systems to discover the system default password.
While Stuxnet only affected Windows machines with infected USB drives plugged in, the Windows Shortcut Exploit in general can work through file shares and WebDav as well.
Am I at risk?
At the moment, there is no patch from Microsoft to fix this exploit; however, our free Windows Shortcut Exploit Protection Tool will block this exploit from running on your computer. Sophos customers are already protected from this exploit.
The Windows Shortcut Exploit affects all Microsoft-supported versions of Windows—anything newer than Windows XP SP3—as well as older versions.
Sophos Security Chet-Chat Episode 19:
The Windows Shortcut Exploit/CPLINK – What is it, what are the risks?
13:21 minutes – Download (12.2 MB)
How do I protect against this?
Download our free Windows Shortcut Exploit Protection Tool to block the exploit from running on your computer. If you’re an existing Sophos Endpoint customer, you are already safe from this exploit.
Microsoft’s officially recommends disabling icon rendering; however, this advice could make Windows significantly harder to use.
How To Disable Disable Autoplay of USB Drives ( USB AutoRun )
April 20, 2009 by admin
Filed under Protection Tools
To Disable USB Autorun, go to Start Menu > Run and type in :
gpedit.msc
You will see the Group Policy window. You should select Administrative Templates \ System in the tree view:
















