All the latest UK technology news, reviews and analysis

Patch now or suffer Sasser

by vnunet.com staff

04 May 2004

Be the first to comment

  • Tweet this

Microsoft customers are being urged to update their patches to protect against a family of internet worms that are spreading fast by exploiting a vulnerability in Windows.

The Sasser worms exploit the Windows Local Security Authority Subsystem Service flaw, about which Microsoft has already advised users. Four variants of the worm have been reported since 1 May.

Security software firm McAfee warned that systems are especially at risk, as the virus does not spread via email and no user action is required to propagate it. The worm simply instructs vulnerable systems to download and execute its code.

"Computers which are not properly protected with antivirus updates, firewalls and Microsoft's security patches are asking for trouble," warned Graham Cluley, senior technology consultant at antivirus firm Sophos.

Luis Corrons, a director at Panda Software, said that Sasser looked like a dangerously virulent worm.

"All these signs make for a dark forecast for the beginning of the week when it is expected that the number of incidents will soar at the start of the working day," he said in a statement.

The worm scans random IP addresses for vulnerable systems, then sends a specially crafted packet to produce a buffer overrun on LSASS.EXE. This causes the program and infected system to crash, requiring Windows to reboot.

"More infections can lead to increased network traffic and result in severe network slowdowns, like an internal denial-of-service attack," said Joe Hartmann, senior virus researcher and analyst at Trend Micro.

The worm affects Windows 95, 98, ME, NT, 2000 and XP. Customers are advised to apply the necessary patches immediately. The Microsoft patches can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Project Manager (BI)

Project Manager (BI) 6 Months Contract – to...

Desktop Support Manager

Desktop Support Manager 3 month contract - to start...

Programme Manager / 45k ++ Benefits / London

/ Programme Manager / 45k / Significant benefits / London...

Automation Test Manager Selenium London 75k

Automation Test Manager Selenium London 75k Automation...

To send to more than one email address, simply separate each address with a comma.