漏洞描述
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attackers to download arbitrary programs onto a Windows PC, and execute these programs, via a request to TCP port 7777.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.symantec.comhttp://www.symantec.com/connect/blogs/trojan-found-usb-battery-charger-software↗www.marketwatch.comhttp://www.marketwatch.com/story/energizer-announces-duo-charger-and-usb-charger-software-problem-2010-03-05↗www.kb.cert.orghttp://www.kb.cert.org/vuls/id/154421↗www.securityfocus.comhttp://www.securityfocus.com/bid/38571↗