in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Suspicious System Call

Last post 04-01-2008 2:01 PM by Free. 3 replies.
Page 1 of 1 (4 items)
Sort Posts: Previous Next
  • 03-31-2008 1:37 PM

    Suspicious System Call

     Event ID:

    BLINK-APP-100

     Severity: High
     Description: Blink detected a suspicious system call.
     Reason: ADVAPI32.DLL!RegOpenKeyExW
     Action: Terminate Process
     Program: C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
     Alert: Yes
     Note: Blink detected an abnormal behavior in one of the monitored applications. It is very likely that you are witnessing an attempt to exploit a known or unknown buffer overflow vulnerability in this application. The best course of action is to update this application to the latest version available from its vendor. Also, please report this issue to eEye to be investigated further. If you are sure that this is not an attack, you can disable the Application Protection layer for this application by editing the apiex.ini file in the Config folder under the Blink installation directory.

    To add an exclusion for this application, open the file in notepad or your favorite text editor and add a line in this format: PROCESS_NAME;;Kevlar;0
    Replace the PROCESS_NAME entry above with the .exe name reported above in this event. For example, to exclude notepad.exe create an entry like this: notepad.exe;;Kevlar;0

     

    I got this message reguarding my Office 2007 Word application, and it suggests I report this issue to eEye to be investigate further, but there is no easy way I can find on the page or in the program options to report this. If you are on the event log item, it would be nice to right click on the item or highlight the items you want and have an option to send the report directly to the appropriate department at eEye for further investigation. I am totally up to date on Microsoft Updates, so something must be going on that Microsoft doesn't yet know about or have fixed. I had filled out an on-line petition, and copied my comments and pasted them into a Word document so I could save them. 

    Filed under: ,
  • 03-31-2008 6:03 PM In reply to

    Re: Suspicious System Call

    Have a look at this post I made here on those alerts and see if it helps you: 

    http://forums.eeye.com/forums/p/54/140.aspx#140 

    Filed under: ,
  • 03-31-2008 7:26 PM In reply to

    • Free
    • Top 25 Contributor
    • Joined on 03-30-2008
    • Posts 25

    Re: Suspicious System Call

    I have Office 2007 Professional installed here and it is working fine. Can you tell me at what point in using Word07 you encounter this and I will see if I can reproduce the same thing.

  • 04-01-2008 2:01 PM In reply to

    • Free
    • Top 25 Contributor
    • Joined on 03-30-2008
    • Posts 25

    Re: Suspicious System Call

    You should save as XPS document type instead of copy/pasting into MS Word 07. If you go to the installed printers, the XPS document writer should be there.

Page 1 of 1 (4 items)
© 1995 - 2009 eEye Incorporated