Exploit-TaroDrop.d - Cyber Espionage in Reality:Computer Security Research - McAfee Avert Labs Blog

一太郎のZero-DayとパッチについてのMcAfeeの記事ですが、やっぱり、企業や政府系で標的方攻撃で使われるってのが一番怖いよなぁ。

Last Thursday, McAfee Avert Labs picked up another 0-day vulnerability targeting the JustSystems Ichitaro office application in-the-wild, the fourth since August 2006. Targeted attacks were directed at multiple enterprise and government users of Ichitaro in Japan, using two versions of a maliciously crafted Ichitaro document. Both exploits installs the same BackDoor-DLI trojan payload.

screenshot