{"id":11894,"date":"2011-11-08T18:46:00","date_gmt":"2011-11-08T18:46:00","guid":{"rendered":"https:\/\/aidanfinn.com\/?p=11894"},"modified":"2011-11-08T18:46:00","modified_gmt":"2011-11-08T18:46:00","slug":"microsoft-issues-duqu-workaround-msa-2639658cve-2011-3402","status":"publish","type":"post","link":"https:\/\/aidanfinn.com\/?p=11894","title":{"rendered":"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402)"},"content":{"rendered":"<p>In the last couple of weeks we\u2019ve heard quite a bit about the alleged \u201cStuxnet\u201d variant called <a href=\"http:\/\/en.wikipedia.org\/wiki\/Duqu\">Duqu<\/a>.&#160; This Trojan uses a zero-day vulnerability that exploits the TrueType font parsing engine.&#160; The Trojan replicates itself, <a href=\"http:\/\/www.symantec.com\/connect\/w32-duqu_status-updates_installer-zero-day-exploit\">does whatever it does<\/a> (still not entirely clear), and removes itself after 36 days to avoid detection.&#160; That last bit is sneaky; it could steal passwords or certs, high-tail it before the heat arrives, and you\u2019d never know to reset anything that was stolen.&#160; Very clever!<\/p>\n<p>While Microsoft are working on a hotfix, they have issued an advisory that contains a workaround to prevent <a href=\"http:\/\/technet.microsoft.com\/en-us\/security\/advisory\/2639658\">infection<\/a>.&#160; The actions depend on your operating system, but revolve around changing the permissions of t2embed.dll.<\/p>\n<p>I\u2019ve become very hesitant of these workarounds.&#160; A few months ago I worked on a site that had no choice but to deploy such a workaround for Conficker.<\/p>\n<p>I was installing a ConfigMgr 2007 R3 site server.&#160; I installed ConfigMgr and checked the health of the system (it\u2019s easy to miss a pre-req and get some sort of error).&#160; Then I got the strangest error that I had never seen before; the management point role would not install.&#160; What normally happens is the site server is installed (not far from next-next-next), and then a number of default roles install automatically.&#160; The management point is usually painless.&#160; I googled, binged, you name it, and had no joy.&#160; A day later and 2 things gave me the solution:<\/p>\n<ol>\n<li>I had been told of the Conficker infection and clean up job that was done<\/li>\n<li>I found an obscure post with a similar error that pointed to a system registry key permissions issue.<\/li>\n<\/ol>\n<p>1 + 1 and I verified this key was a part of the Microsoft Conficker workaround advisory.&#160; Now, I needed to find how this was deployed.&#160; GPMC made it easy to find a GPO that was responsible.&#160; Permission changes via GPO are tattooed so I reversed the edits (AV was up to date).&#160; I forced the policy refresh on the site server, reran the ConfigMgr install and the Management Point installed.&#160; Luckily the customer <em>had <\/em>used GPO and made this workaround very easy deploy for them, and ID\/reverse for me.<\/p>\n<p>By the way, part of the change was changing permissions of scheduled tasks.&#160; It turns out that backup jobs hadn\u2019t been running correctly for a while.<\/p>\n<p>So the lesson is:<\/p>\n<ul>\n<li>When there is a zero-day exploit, Microsoft can issue workarounds to prevent infection.<\/li>\n<li>Sometimes treatment for an illness can do quite a lot of damage to the patient.&#160; Understand what you are doing and document\/communicate it.<\/li>\n<li>If at all possible, do what my customer did.&#160; Use a GPO because it is (a) fast to deploy and (b) fast to reverse once the long term defences (patch\/AV) are deployed.&#160; And that means impacted systems can be put back to rights.<\/li>\n<\/ul>\n<div style=\"padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px\" id=\"scid:0767317B-992E-4b12-91E0-4F059A8CECA8:ad6b49a7-604a-48a4-9348-5f86332c810e\" class=\"wlWriterEditableSmartContent\">Technorati Tags: <a href=\"http:\/\/technorati.com\/tags\/Microsoft\" rel=\"tag\">Microsoft<\/a>,<a href=\"http:\/\/technorati.com\/tags\/Security\" rel=\"tag\">Security<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>In the last couple of weeks we\u2019ve heard quite a bit about the alleged \u201cStuxnet\u201d variant called Duqu.&#160; This Trojan uses a zero-day vulnerability that exploits the TrueType font parsing engine.&#160; The Trojan replicates itself, does whatever it does (still not entirely clear), and removes itself after 36 days to avoid detection.&#160; That last bit &hellip; <a href=\"https:\/\/aidanfinn.com\/?p=11894\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402)&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[37],"tags":[185,190],"class_list":["post-11894","post","type-post","status-publish","format-standard","hentry","category-security","tag-microsoft","tag-security"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"In the last couple of weeks we\u2019ve heard quite a bit about the alleged \u201cStuxnet\u201d variant called Duqu. This Trojan uses a zero-day vulnerability that exploits the TrueType font parsing engine. The Trojan replicates itself, does whatever it does (still not entirely clear), and removes itself after 36 days to avoid detection. That last bit\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"AFinn\"\/>\n\t<meta name=\"google-site-verification\" content=\"TDKjbi2McB2eLIfL6KwPB3aQqv5E-mbcb2QYIcovGaI\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/aidanfinn.com\/?p=11894\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_GB\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Aidan Finn, IT Pro - A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402) | Aidan Finn, IT Pro\" \/>\n\t\t<meta property=\"og:description\" content=\"In the last couple of weeks we\u2019ve heard quite a bit about the alleged \u201cStuxnet\u201d variant called Duqu. This Trojan uses a zero-day vulnerability that exploits the TrueType font parsing engine. The Trojan replicates itself, does whatever it does (still not entirely clear), and removes itself after 36 days to avoid detection. That last bit\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/aidanfinn.com\/?p=11894\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2011-11-08T18:46:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2011-11-08T18:46:00+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@joe_elway\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402) | Aidan Finn, IT Pro\" \/>\n\t\t<meta name=\"twitter:description\" content=\"In the last couple of weeks we\u2019ve heard quite a bit about the alleged \u201cStuxnet\u201d variant called Duqu. This Trojan uses a zero-day vulnerability that exploits the TrueType font parsing engine. The Trojan replicates itself, does whatever it does (still not entirely clear), and removes itself after 36 days to avoid detection. That last bit\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@joe_elway\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#article\",\"name\":\"Microsoft Issues Duqu Workaround (MSA 2639658\\\/CVE-2011-3402) | Aidan Finn, IT Pro\",\"headline\":\"Microsoft Issues Duqu Workaround (MSA 2639658\\\/CVE-2011-3402)\",\"author\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#articleImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"},\"datePublished\":\"2011-11-08T18:46:00+00:00\",\"dateModified\":\"2011-11-08T18:46:00+00:00\",\"inLanguage\":\"en-GB\",\"commentCount\":2,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#webpage\"},\"articleSection\":\"Security, Microsoft, Security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/aidanfinn.com\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=37#listItem\",\"name\":\"Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=37#listItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=37\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#listItem\",\"name\":\"Microsoft Issues Duqu Workaround (MSA 2639658\\\/CVE-2011-3402)\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#listItem\",\"position\":3,\"name\":\"Microsoft Issues Duqu Workaround (MSA 2639658\\\/CVE-2011-3402)\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=37#listItem\",\"name\":\"Security\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\",\"name\":\"AFinn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1\",\"name\":\"AFinn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#webpage\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894\",\"name\":\"Microsoft Issues Duqu Workaround (MSA 2639658\\\/CVE-2011-3402) | Aidan Finn, IT Pro\",\"description\":\"In the last couple of weeks we\\u2019ve heard quite a bit about the alleged \\u201cStuxnet\\u201d variant called Duqu. This Trojan uses a zero-day vulnerability that exploits the TrueType font parsing engine. The Trojan replicates itself, does whatever it does (still not entirely clear), and removes itself after 36 days to avoid detection. That last bit\",\"inLanguage\":\"en-GB\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=11894#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"datePublished\":\"2011-11-08T18:46:00+00:00\",\"dateModified\":\"2011-11-08T18:46:00+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#website\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/\",\"name\":\"Aidan Finn, IT Pro\",\"description\":\"A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...\",\"inLanguage\":\"en-GB\",\"publisher\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402) | Aidan Finn, IT Pro","description":"In the last couple of weeks we\u2019ve heard quite a bit about the alleged \u201cStuxnet\u201d variant called Duqu. This Trojan uses a zero-day vulnerability that exploits the TrueType font parsing engine. The Trojan replicates itself, does whatever it does (still not entirely clear), and removes itself after 36 days to avoid detection. That last bit","canonical_url":"https:\/\/aidanfinn.com\/?p=11894","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"TDKjbi2McB2eLIfL6KwPB3aQqv5E-mbcb2QYIcovGaI","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/aidanfinn.com\/?p=11894#article","name":"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402) | Aidan Finn, IT Pro","headline":"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402)","author":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"publisher":{"@id":"https:\/\/aidanfinn.com\/#person"},"image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=11894#articleImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"},"datePublished":"2011-11-08T18:46:00+00:00","dateModified":"2011-11-08T18:46:00+00:00","inLanguage":"en-GB","commentCount":2,"mainEntityOfPage":{"@id":"https:\/\/aidanfinn.com\/?p=11894#webpage"},"isPartOf":{"@id":"https:\/\/aidanfinn.com\/?p=11894#webpage"},"articleSection":"Security, Microsoft, Security"},{"@type":"BreadcrumbList","@id":"https:\/\/aidanfinn.com\/?p=11894#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/aidanfinn.com#listItem","position":1,"name":"Home","item":"https:\/\/aidanfinn.com","nextItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=37#listItem","name":"Security"}},{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=37#listItem","position":2,"name":"Security","item":"https:\/\/aidanfinn.com\/?cat=37","nextItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?p=11894#listItem","name":"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402)"},"previousItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?p=11894#listItem","position":3,"name":"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402)","previousItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=37#listItem","name":"Security"}}]},{"@type":"Person","@id":"https:\/\/aidanfinn.com\/#person","name":"AFinn","image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=11894#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"}},{"@type":"Person","@id":"https:\/\/aidanfinn.com\/?author=1#author","url":"https:\/\/aidanfinn.com\/?author=1","name":"AFinn","image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=11894#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"}},{"@type":"WebPage","@id":"https:\/\/aidanfinn.com\/?p=11894#webpage","url":"https:\/\/aidanfinn.com\/?p=11894","name":"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402) | Aidan Finn, IT Pro","description":"In the last couple of weeks we\u2019ve heard quite a bit about the alleged \u201cStuxnet\u201d variant called Duqu. This Trojan uses a zero-day vulnerability that exploits the TrueType font parsing engine. The Trojan replicates itself, does whatever it does (still not entirely clear), and removes itself after 36 days to avoid detection. That last bit","inLanguage":"en-GB","isPartOf":{"@id":"https:\/\/aidanfinn.com\/#website"},"breadcrumb":{"@id":"https:\/\/aidanfinn.com\/?p=11894#breadcrumblist"},"author":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"creator":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"datePublished":"2011-11-08T18:46:00+00:00","dateModified":"2011-11-08T18:46:00+00:00"},{"@type":"WebSite","@id":"https:\/\/aidanfinn.com\/#website","url":"https:\/\/aidanfinn.com\/","name":"Aidan Finn, IT Pro","description":"A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...","inLanguage":"en-GB","publisher":{"@id":"https:\/\/aidanfinn.com\/#person"}}]},"og:locale":"en_GB","og:site_name":"Aidan Finn, IT Pro - A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...","og:type":"article","og:title":"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402) | Aidan Finn, IT Pro","og:description":"In the last couple of weeks we\u2019ve heard quite a bit about the alleged \u201cStuxnet\u201d variant called Duqu. This Trojan uses a zero-day vulnerability that exploits the TrueType font parsing engine. The Trojan replicates itself, does whatever it does (still not entirely clear), and removes itself after 36 days to avoid detection. That last bit","og:url":"https:\/\/aidanfinn.com\/?p=11894","article:published_time":"2011-11-08T18:46:00+00:00","article:modified_time":"2011-11-08T18:46:00+00:00","twitter:card":"summary","twitter:site":"@joe_elway","twitter:title":"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402) | Aidan Finn, IT Pro","twitter:description":"In the last couple of weeks we\u2019ve heard quite a bit about the alleged \u201cStuxnet\u201d variant called Duqu. This Trojan uses a zero-day vulnerability that exploits the TrueType font parsing engine. The Trojan replicates itself, does whatever it does (still not entirely clear), and removes itself after 36 days to avoid detection. That last bit","twitter:creator":"@joe_elway"},"aioseo_meta_data":{"post_id":"11894","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2020-12-21 03:53:18","updated":"2025-06-04 14:45:53","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/aidanfinn.com\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/aidanfinn.com\/?cat=37\" title=\"Security\">Security<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tMicrosoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402)\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/aidanfinn.com"},{"label":"Security","link":"https:\/\/aidanfinn.com\/?cat=37"},{"label":"Microsoft Issues Duqu Workaround (MSA 2639658\/CVE-2011-3402)","link":"https:\/\/aidanfinn.com\/?p=11894"}],"jetpack_featured_media_url":"","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/11894","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11894"}],"version-history":[{"count":0,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/11894\/revisions"}],"wp:attachment":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}