Discovered: November 8, 2004
Updated: February 13, 2007 12:29:41 PM
Type: Trojan Horse, Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Bloodhound.Exploit.18 is a heuristic detection for HTML files attempting to exploit the recent Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability discovered in Internet Explorer 6.0. The vulnerability is still unpatched by Microsoft as of November 8, 2004.
Recent variants of the Mydoom family of worms attempt to exploit this vulnerability to spread. The downloader component of such worms may be detected as Bloodhound.Exploit.18.
Protection
-
Initial Rapid Release version November 8, 2004
-
Latest Rapid Release version July 12, 2008 revision 018
-
Initial Daily Certified version October 31, 2007 revision 003
-
Latest Daily Certified version July 12, 2008 revision 019
-
Initial Weekly Certified release date November 8, 2004
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
-
Wild Level: Low
-
Number of Infections: 0 - 49
-
Number of Sites: 0 - 2
-
Geographical Distribution: Low
-
Threat Containment: Easy
-
Removal: Easy
Damage
Distribution