On CNET: Kazaa to return as subscription service
BNET Business Network:
BNET
TechRepublic
ZDNet

October 28th, 2008

Exploit published for Windows worm hole

Posted by Ryan Naraine @ 1:40 pm

Categories: Arbitrary Code Execution, Browsers, Complex Attacks, Data theft, Exploit code, Hackers, Malware, Metasploit, Passwords, Patch Watch, Responsible disclosure, Windows Vista, Zero-day attacks

Tags: Microsoft Windows Server, Microsoft Corp., Exploit, Windows Server Service, Microsoft Windows, RPC, Operating Systems, Servers, Software, Networking

Exploit published for Windows worm holeReliable exploit code for the remote code execution vulnerability patched with Microsoft’s MS08-067 update has been posted to the Internet, prompting a new “patch immediately” advisory from the Redmond software maker.

The exploit, which has been added to the freely available Metasploit point-and-click attack tool, provides a roadmap for code execution on Windows 2000, Windows XP, and Windows Server 2003.   A second exploit has been posted to Milw0rm.com, increasing the likelihood of in-the-wild malware attacks.

[ SEE: MS ships emergency patch for Windows worm hole ]

From the Microsoft advisory:

  • Our investigation of this exploit code has verified that it does not affect customers who have installed the updates detailed in MS08-067 on their computers.  Microsoft continues to recommend that customers apply the updates to the affected products by enabling the Automatic Updates feature in Windows.

Several proof-of-concepts have also been publicly released.

Microsoft shipped an out-of-band update last week to plug the hole after discovering “limited, targeted attacks” against Windows users.   The attacks included the use of  reconnaissance Trojans hijacking sensitive system information.

The vulnerability is due to the Windows Server service not properly handling specially crafted RPC requests.  The vulnerable Windows Server service provides RPC support, file and print support, and named pipe sharing over the network. It is also used to allow the sharing of your local resources (such as disks and printers) so that other users on the network can access them.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 13 Talkback(s)
Correcting the corrections
A) "that there were no confirmed exploits in the wild. Which is why it's big news that there is one today."

From the article

"Microsoft shipped an out-of-band update last week to plug th... (Read the rest)
Posted by: Richard Flude Posted on: 10/29/08 You are currently: a Guest | | Terms of Use
This is no big deal, right?  NonZealot | 10/28/08
Phew, that's lucky  Richard Flude | 10/28/08
Vista?  wandah@... | 10/29/08
Vista's pretty darned good actually  medezark@... | 10/29/08
Factually incorrect... as usual  bmerc | 10/29/08
It's funny...  LiquidLearner | 10/29/08
Correcting the corrections  Richard Flude | 10/29/08
You're posting this just now?  carolannie | 10/29/08
on Vista the worm doesn't work  qmlscycrajg | 10/29/08
It Will If UAC Is Disabled and prompts silenced.  dunn@... | 10/29/08
lol  rtk | 10/29/08
RE: Exploit published for Windows worm hole  TheBrainchildGroup | 10/29/08
Windows security freak show  Chad_z | 10/29/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
advertisement
Click Here