All the latest UK technology news, reviews and analysis

Microsoft Patch Tuesday exploit surfaces

by Tom Sanders in California

11 Aug 2006

Comments: 2

  • Tweet this

Malware authors have crafted an exploit that attacks a security vulnerability patched by Microsoft as part of last Tuesday's security update.

The attack uses a vulnerability that Microsoft described in security bulletin MS06-040. It describes a buffer overflow vulnerability in the Windows Server component, affecting Windows 2000, Windows XP and Windows Server 2003.

The exploit only works on systems running Windows 2000 or Windows XP without any service packs. Most Window XP systems run service pack 2.

Attackers can contact the affected component through TCP ports 139 and 445. Both ports are used for NetBIOS sessions including Windows File and Printer sharing.

The exploit prompted the US Department of Homeland Security to issue a press release urging users to apply Tuesday's patch.

Few security experts were surprised by the speed at which online criminals started exploiting the vulnerability.

Bojan Zdrnja with the SANS Internet Storm Center and a security researcher for the University of Auckland warned that the code will cause more widespread attacks as less sophisticated virus writers start creating copy-cat malware.

"It's just a matter of time when script kiddies will start using this, if they haven't already," said Zdrnja.

"We can expect that this exploit will soon be added to the attack arsenal of bots such as Sdbot and similar. In other words – patch!"

The MS06-040 exploit marks the first attack new following this week's Microsoft patch release.

The patch plugged 23 security vulnerabilities, 11 of which were actively being exploited at the time of the release.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Web Graphic Designer

A leading global provider of critical information to...

Midweight UI Designer

Playstations and table football in the kitchen? Standard...

Systems Engineer - 2nd/3rd Line Support - Microsoft + Citrix OR VMware

Systems Engineer - 2nd/3rd Line Support - Microsoft OS...

Senior Network Engineer

A leading global provider of critical information to...

To send to more than one email address, simply separate each address with a comma.